SlideShare una empresa de Scribd logo
1 de 30
Descargar para leer sin conexión
Becky Wagner, Sr BI Architect
E: bwagner@us-analytics.com T: @Bec_Wagner
Active Directory and Single Sign-On
with Oracle Analytics Cloud (OAC)
October 24th, 2018 Oracle Open World Marquis Nob Hill C/D
https://www.us-analytics.com/oac-active-directory-single-sign-on
2
AGENDA
OAC Options – Customer Case1
AD Bridge2
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
3
BECKY WAGNER
WHO AM I?
§ Wife; Mother of 3 (ages 16, 13, and 9);
§ 2nd degree black belt in Tae Kwon Do
§ Red Cross Blood Drive Coordinator
§ ODTUG BI Community Leader
§ Oracle ACE Associate
§ Sr BI Architect at US-Analytics
§ 14 years in IT
§ Email: bwagner@us-analytics.com
§ Twitter: @Bec_Wagner
§ LinkedIn: https://www.linkedin.com/in/rebecca-wagner-bb356924/
§ IRC Channel (Telegram): #obihackers
3 Membership Tiers
• Oracle ACE Director
• Oracle ACE
• Oracle ACE Associate
bit.ly/OracleACEProgram
500+ Technical Experts
Helping Peers Globally
Connect:
Nominate yourself or someone you know: acenomination.oracle.com
@oracleace
Facebook.com/oracleaces
oracle-ace_ww@oracle.com
7
Who is US-Analytics?
80+
EPM and BI
professionals
with 12+ years of experience.
BY THE NUMBERS
19+years in business
with continued growth
>600clients
1,500+engagements
with
8
TECHNOLOGYENERGY FINANCIAL RETAIILHEALTHCARE
Sampling of EPM Clients (Project and Support) Approx. 100 Projects Annually
9
AGENDA
OAC Options – Customer Case1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
AD Bridge2
10
• Security is highest priority
• Waited to start Project until AD integration
• VPNaaS to Palo Alto NextGen Firewalls
• Private IP Ranges
• Access from within network only
• OAC with IDCS (Identity Cloud)
• Migrating from OBIEE 11g to OAC
• AD integration required (8000+ users, 14000+
groups)
• SSO was highly desirable
Large Financial Management Customer
US-Analytics: Customer Case – Enterprise worthy OAC
11
AGENDA
OAC Options – Customer Case1
AD Bridge2
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
12
AD Bridge
Besides following the tutorial, what you need:
• Must install on Server joined to AD Domain
• User with rights to install software
• User with the following AD rights
• Read for all users and groups in the domain
• Read for all OUs
• If you are using an AD user specifically setup for this AD Bridge, specific permissions
can be found here:
• https://docs.oracle.com/en/cloud/paas/identity-cloud/uaids/creating-
bridge.html
• Tutorial for AD Bridge
• https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs
_idbridge_obe/idbridge.html
13
AD Bridge - Roadmap
1. Download From IDCS
2. Install On Domain-Joined Server
3. Configure Users and Groups
4. Import in IDCS
5. Verify
*Note: OAC comes with IDCS Foundation. AD Bridge is in IDCS Basic.
14
AD Bridge – Detailed Steps Part 1
• Browser - IDCS, navigate to Directory Integration and click Add
• Copy the URL, Client ID and Client Secret
• Click Download
• Click Run and Next, Next, Next
• Enter the URL, ID and Secret and Test
• If successful, click Next
• Enter AD Domain User and Password and Test
• If successful, click Next
1:07
1:15
1:52
1:55
2:12
2:21
2:27
2:31
15
AD Bridge – Detailed Steps Part 2
• Browser – IDCS Directory Integration partially configured
• Expand OU’s and check appropriate OU for Users
• Repeat for groups
• Click Attribute Mappings, delete all non-needed, don’t change
• Save, Refresh, Import
• Verify by clicking on Users tab in left menu
3:07
3:17
3:25
3:32
4:17
5:01
16
AD Bridge, Video Walk-Through
https://youtu.be/QbQV-riohVI
17
AD Bridge – The More You Know
• Becomes a service. Note that this service is running and starts automatically
• Find the AD Bridge Config Utility in C:Program FilesIDBridgeIDBridgeUI.exe
• Click on View Logs – Highly important to note log locations
• Sync has a limit, will continue at the frequency until fully sync’d
• Errors will have details in the logs, like missing email or some other attribute issue
18
AGENDA
OAC Options1
Direct SSO vs Link4
Trouble Spots5
SAML 2.0 ADFS3
AD Bridge2
19
ADFS & Single Sign-On – SAML 101
Img from - https://developers.onelogin.com/assets/img/pages/saml/sso-diagram.svg
20
ADFS & Single Sign-On – Detailed Steps Part 1
1. Download ADFS Metadata File
• https://adfs.contoso.com/FederationMetadata/2007-06/FederationMetatdata.xml
• XML files have tags, if browser doesn’t show them, right click and view source, then save
2. IDCS Identity Provider Setup
• Add SAML IDP
• Name, Next, Upload FederationMetadata.xml, Requested NameID – Email Addr, Next, Finish
• Don’t click Export – Use the following URL to download IDCS metadata XML
• https://MYTENANT.identity.oraclecloud.com/fed/v1/metadata?adfsmode=true
Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html
0:23
1:40
21
ADFS & Single Sign-On – Detailed Steps Part 2
3. In AD FS management console add a Relying Party Trust
• Import Metadata.xml, Next, Name, Next Next Next Next, Finish
• Add Claim Rules
1. Send LDAP Attributes as Claims, Name - Email, Attribute Store - Active Directory,
LDAP Attribute - Email Addresses and Outgoing Claim Type – Email Address
2. Transform an Incoming Claim, Name – Name ID, Incoming – Email Address,
Outgoing claim – Name ID, Outgoing format – Email
4. IDCS Configuration
• Drop down – select Activate, Drop down again – select Show on Login Page
• IDP Policies – Click Default and then Assign new ADFS
Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html
2:43
4:20
22
ADFS & Single Sign-On, Video Walk-Through
https://youtu.be/FcULyV0mgFs
23
AGENDA
OAC Options1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
2 AD Bridge
24
Removing Local Logins
Oracle Support Doc ID 2438952.1
OAC/OAAC: How To Disable IDCS Chooser Login Page and Get Redirected to Custom SSO
Login Page Directly in Oracle Analytics Cloud(OAC)
Once everything has been confirmed working for SSO link on login page:
• IDP Policies
• Remove ADFS from ‘Default Identity Provider Policy’
• Create new IDP Policy
• Assign ADFS to Policy
• Assign OAC Application(s)
• Configure Application for Redirect URL
• Can be any URL (www.oracle.com), and doesn’t actually affect behavior
0:12
0:26
1:05
25
Removing Local Logins, Video Walk-Through
https://youtu.be/Hg5EKV2nmnM
26
AGENDA
OAC Options1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
2 AD Bridge
27
Things to be on the lookout for
Trouble Spots and Lessons Learned
ADFS Direct SSOAD Bridge
• Sometimes logs stop
while still showing
Active in IDCS and
service shows
running in Windows
• Logs path not in
documentation, use
ADBridge Application
and View Logs.
• While checking OUs,
be sure to expand
and check lower
levels (Default now)
• Username - Email
• IDCS uses SAML 2.0,
for Win 2016 we had
to get a different
ADFS xml file
• Don’t download the
Export IDCS
metadata. ADFS
needs a special
format. Can get from
URL:
• https://DOMAIN.oracle
cloud.com/fed/v1/met
adata?adfsmode=true
• Security wants users
to be authenticated
by AD only
• EM, RPD Admin Tool,
Weblogic Console,
still direct login –
Can’t use AD users
• Configure IDP Policy
• Sign Out redirects to
OAC DV, still signed
in. Can configure
ADFS global sign-out
then IDCS sign out
URL
28
11g Migration User Folder name change
Account Rename
29
§ Remove IDCS Chooser Page
§ Still need local login for EM
and Weblogic Console and RPD
Admin Tool
RECAP
OAC Options AD Bridge
SAML 2.0 ADFS Direct SSO or Link
§ Security Sensitive
§ IDCS Private IP
§ Allows for AD and SSO
integration
§ Local AD Domain joined Server
§ Find your logs
§ Find your ADFS buddy
§ Sign Out – redirects to DV
§ Claim Rules only worked with
Email
Getting Fancy: HA AD Bridge – Docker style
https://www.oracle.com/technetwork/articles/idm/gutierrez-idcs-idbridge-3960710.html
Becky Wagner, Sr BI Architect
E: bwagner@us-analytics.com T: @Bec_Wagner
Questions?
October 24th, 2018 Marquis Nob Hill C/DOracle Open World
https://www.us-analytics.com/oac-active-directory-single-sign-on

Más contenido relacionado

La actualidad más candente

Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
Databricks
 

La actualidad más candente (20)

Oracle Analytics Cloud
Oracle Analytics CloudOracle Analytics Cloud
Oracle Analytics Cloud
 
Building a modern data warehouse
Building a modern data warehouseBuilding a modern data warehouse
Building a modern data warehouse
 
Intro to Delta Lake
Intro to Delta LakeIntro to Delta Lake
Intro to Delta Lake
 
How Expedia’s Entity Graph Powers Global Travel
How Expedia’s Entity Graph Powers Global TravelHow Expedia’s Entity Graph Powers Global Travel
How Expedia’s Entity Graph Powers Global Travel
 
A Reference Architecture for ETL 2.0
A Reference Architecture for ETL 2.0 A Reference Architecture for ETL 2.0
A Reference Architecture for ETL 2.0
 
OBIEE ARCHITECTURE.ppt
OBIEE ARCHITECTURE.pptOBIEE ARCHITECTURE.ppt
OBIEE ARCHITECTURE.ppt
 
Faw
FawFaw
Faw
 
E-Business Suite on Oracle Cloud
E-Business Suite on Oracle CloudE-Business Suite on Oracle Cloud
E-Business Suite on Oracle Cloud
 
Intro to Azure Data Factory v1
Intro to Azure Data Factory v1Intro to Azure Data Factory v1
Intro to Azure Data Factory v1
 
From Data Warehouse to Lakehouse
From Data Warehouse to LakehouseFrom Data Warehouse to Lakehouse
From Data Warehouse to Lakehouse
 
20200812 Cbject Detection with OpenCV and CNN
20200812 Cbject Detection with OpenCV and CNN20200812 Cbject Detection with OpenCV and CNN
20200812 Cbject Detection with OpenCV and CNN
 
Delta Lake OSS: Create reliable and performant Data Lake by Quentin Ambard
Delta Lake OSS: Create reliable and performant Data Lake by Quentin AmbardDelta Lake OSS: Create reliable and performant Data Lake by Quentin Ambard
Delta Lake OSS: Create reliable and performant Data Lake by Quentin Ambard
 
Data Mesh 101
Data Mesh 101Data Mesh 101
Data Mesh 101
 
Azure Data Factory v2
Azure Data Factory v2Azure Data Factory v2
Azure Data Factory v2
 
Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
Enterprise Data Governance and Compliance at Scale with Sri Eshasubbiah and S...
 
Azure datafactory
Azure datafactoryAzure datafactory
Azure datafactory
 
Microsoft Fabric Introduction
Microsoft Fabric IntroductionMicrosoft Fabric Introduction
Microsoft Fabric Introduction
 
Talend Open Studio Introduction - OSSCamp 2014
Talend Open Studio Introduction - OSSCamp 2014Talend Open Studio Introduction - OSSCamp 2014
Talend Open Studio Introduction - OSSCamp 2014
 
GoldenGateテクニカルセミナー4「テクニカルコンサルタントが語るOracle GoldenGate現場で使える極意」(2016/5/11)
GoldenGateテクニカルセミナー4「テクニカルコンサルタントが語るOracle GoldenGate現場で使える極意」(2016/5/11)GoldenGateテクニカルセミナー4「テクニカルコンサルタントが語るOracle GoldenGate現場で使える極意」(2016/5/11)
GoldenGateテクニカルセミナー4「テクニカルコンサルタントが語るOracle GoldenGate現場で使える極意」(2016/5/11)
 
Fusion Middleware Oracle Data Integrator
Fusion Middleware Oracle Data IntegratorFusion Middleware Oracle Data Integrator
Fusion Middleware Oracle Data Integrator
 

Similar a AD SSO with Oracle Analytics Cloud - Oracle Open World 18

Fusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons LearnedFusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons Learned
Andrejs Karpovs
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
David Pechon
 
Using Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management ChallengesUsing Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management Challenges
Michael Collier
 

Similar a AD SSO with Oracle Analytics Cloud - Oracle Open World 18 (20)

20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic way20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic way
 
O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365
 
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
 
Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
 
Forge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with ForgeForge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with Forge
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 
From desktop to the cloud with forge
From desktop to the cloud with forgeFrom desktop to the cloud with forge
From desktop to the cloud with forge
 
Fusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons LearnedFusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons Learned
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD Deployment
 
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
 
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
 
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure ADBlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
 
RightScale Webinar: Get Your App To Azure
RightScale Webinar:  Get Your App To AzureRightScale Webinar:  Get Your App To Azure
RightScale Webinar: Get Your App To Azure
 
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
 
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environmentDEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
 
Using Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management ChallengesUsing Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management Challenges
 
CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018
 
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise DirectoryCause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
 

Último

EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
Earley Information Science
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 

AD SSO with Oracle Analytics Cloud - Oracle Open World 18

  • 1. Becky Wagner, Sr BI Architect E: bwagner@us-analytics.com T: @Bec_Wagner Active Directory and Single Sign-On with Oracle Analytics Cloud (OAC) October 24th, 2018 Oracle Open World Marquis Nob Hill C/D https://www.us-analytics.com/oac-active-directory-single-sign-on
  • 2. 2 AGENDA OAC Options – Customer Case1 AD Bridge2 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5
  • 3. 3 BECKY WAGNER WHO AM I? § Wife; Mother of 3 (ages 16, 13, and 9); § 2nd degree black belt in Tae Kwon Do § Red Cross Blood Drive Coordinator § ODTUG BI Community Leader § Oracle ACE Associate § Sr BI Architect at US-Analytics § 14 years in IT § Email: bwagner@us-analytics.com § Twitter: @Bec_Wagner § LinkedIn: https://www.linkedin.com/in/rebecca-wagner-bb356924/ § IRC Channel (Telegram): #obihackers
  • 4.
  • 5.
  • 6. 3 Membership Tiers • Oracle ACE Director • Oracle ACE • Oracle ACE Associate bit.ly/OracleACEProgram 500+ Technical Experts Helping Peers Globally Connect: Nominate yourself or someone you know: acenomination.oracle.com @oracleace Facebook.com/oracleaces oracle-ace_ww@oracle.com
  • 7. 7 Who is US-Analytics? 80+ EPM and BI professionals with 12+ years of experience. BY THE NUMBERS 19+years in business with continued growth >600clients 1,500+engagements with
  • 8. 8 TECHNOLOGYENERGY FINANCIAL RETAIILHEALTHCARE Sampling of EPM Clients (Project and Support) Approx. 100 Projects Annually
  • 9. 9 AGENDA OAC Options – Customer Case1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 AD Bridge2
  • 10. 10 • Security is highest priority • Waited to start Project until AD integration • VPNaaS to Palo Alto NextGen Firewalls • Private IP Ranges • Access from within network only • OAC with IDCS (Identity Cloud) • Migrating from OBIEE 11g to OAC • AD integration required (8000+ users, 14000+ groups) • SSO was highly desirable Large Financial Management Customer US-Analytics: Customer Case – Enterprise worthy OAC
  • 11. 11 AGENDA OAC Options – Customer Case1 AD Bridge2 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5
  • 12. 12 AD Bridge Besides following the tutorial, what you need: • Must install on Server joined to AD Domain • User with rights to install software • User with the following AD rights • Read for all users and groups in the domain • Read for all OUs • If you are using an AD user specifically setup for this AD Bridge, specific permissions can be found here: • https://docs.oracle.com/en/cloud/paas/identity-cloud/uaids/creating- bridge.html • Tutorial for AD Bridge • https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs _idbridge_obe/idbridge.html
  • 13. 13 AD Bridge - Roadmap 1. Download From IDCS 2. Install On Domain-Joined Server 3. Configure Users and Groups 4. Import in IDCS 5. Verify *Note: OAC comes with IDCS Foundation. AD Bridge is in IDCS Basic.
  • 14. 14 AD Bridge – Detailed Steps Part 1 • Browser - IDCS, navigate to Directory Integration and click Add • Copy the URL, Client ID and Client Secret • Click Download • Click Run and Next, Next, Next • Enter the URL, ID and Secret and Test • If successful, click Next • Enter AD Domain User and Password and Test • If successful, click Next 1:07 1:15 1:52 1:55 2:12 2:21 2:27 2:31
  • 15. 15 AD Bridge – Detailed Steps Part 2 • Browser – IDCS Directory Integration partially configured • Expand OU’s and check appropriate OU for Users • Repeat for groups • Click Attribute Mappings, delete all non-needed, don’t change • Save, Refresh, Import • Verify by clicking on Users tab in left menu 3:07 3:17 3:25 3:32 4:17 5:01
  • 16. 16 AD Bridge, Video Walk-Through https://youtu.be/QbQV-riohVI
  • 17. 17 AD Bridge – The More You Know • Becomes a service. Note that this service is running and starts automatically • Find the AD Bridge Config Utility in C:Program FilesIDBridgeIDBridgeUI.exe • Click on View Logs – Highly important to note log locations • Sync has a limit, will continue at the frequency until fully sync’d • Errors will have details in the logs, like missing email or some other attribute issue
  • 18. 18 AGENDA OAC Options1 Direct SSO vs Link4 Trouble Spots5 SAML 2.0 ADFS3 AD Bridge2
  • 19. 19 ADFS & Single Sign-On – SAML 101 Img from - https://developers.onelogin.com/assets/img/pages/saml/sso-diagram.svg
  • 20. 20 ADFS & Single Sign-On – Detailed Steps Part 1 1. Download ADFS Metadata File • https://adfs.contoso.com/FederationMetadata/2007-06/FederationMetatdata.xml • XML files have tags, if browser doesn’t show them, right click and view source, then save 2. IDCS Identity Provider Setup • Add SAML IDP • Name, Next, Upload FederationMetadata.xml, Requested NameID – Email Addr, Next, Finish • Don’t click Export – Use the following URL to download IDCS metadata XML • https://MYTENANT.identity.oraclecloud.com/fed/v1/metadata?adfsmode=true Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html 0:23 1:40
  • 21. 21 ADFS & Single Sign-On – Detailed Steps Part 2 3. In AD FS management console add a Relying Party Trust • Import Metadata.xml, Next, Name, Next Next Next Next, Finish • Add Claim Rules 1. Send LDAP Attributes as Claims, Name - Email, Attribute Store - Active Directory, LDAP Attribute - Email Addresses and Outgoing Claim Type – Email Address 2. Transform an Incoming Claim, Name – Name ID, Incoming – Email Address, Outgoing claim – Name ID, Outgoing format – Email 4. IDCS Configuration • Drop down – select Activate, Drop down again – select Show on Login Page • IDP Policies – Click Default and then Assign new ADFS Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html 2:43 4:20
  • 22. 22 ADFS & Single Sign-On, Video Walk-Through https://youtu.be/FcULyV0mgFs
  • 23. 23 AGENDA OAC Options1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 2 AD Bridge
  • 24. 24 Removing Local Logins Oracle Support Doc ID 2438952.1 OAC/OAAC: How To Disable IDCS Chooser Login Page and Get Redirected to Custom SSO Login Page Directly in Oracle Analytics Cloud(OAC) Once everything has been confirmed working for SSO link on login page: • IDP Policies • Remove ADFS from ‘Default Identity Provider Policy’ • Create new IDP Policy • Assign ADFS to Policy • Assign OAC Application(s) • Configure Application for Redirect URL • Can be any URL (www.oracle.com), and doesn’t actually affect behavior 0:12 0:26 1:05
  • 25. 25 Removing Local Logins, Video Walk-Through https://youtu.be/Hg5EKV2nmnM
  • 26. 26 AGENDA OAC Options1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 2 AD Bridge
  • 27. 27 Things to be on the lookout for Trouble Spots and Lessons Learned ADFS Direct SSOAD Bridge • Sometimes logs stop while still showing Active in IDCS and service shows running in Windows • Logs path not in documentation, use ADBridge Application and View Logs. • While checking OUs, be sure to expand and check lower levels (Default now) • Username - Email • IDCS uses SAML 2.0, for Win 2016 we had to get a different ADFS xml file • Don’t download the Export IDCS metadata. ADFS needs a special format. Can get from URL: • https://DOMAIN.oracle cloud.com/fed/v1/met adata?adfsmode=true • Security wants users to be authenticated by AD only • EM, RPD Admin Tool, Weblogic Console, still direct login – Can’t use AD users • Configure IDP Policy • Sign Out redirects to OAC DV, still signed in. Can configure ADFS global sign-out then IDCS sign out URL
  • 28. 28 11g Migration User Folder name change Account Rename
  • 29. 29 § Remove IDCS Chooser Page § Still need local login for EM and Weblogic Console and RPD Admin Tool RECAP OAC Options AD Bridge SAML 2.0 ADFS Direct SSO or Link § Security Sensitive § IDCS Private IP § Allows for AD and SSO integration § Local AD Domain joined Server § Find your logs § Find your ADFS buddy § Sign Out – redirects to DV § Claim Rules only worked with Email Getting Fancy: HA AD Bridge – Docker style https://www.oracle.com/technetwork/articles/idm/gutierrez-idcs-idbridge-3960710.html
  • 30. Becky Wagner, Sr BI Architect E: bwagner@us-analytics.com T: @Bec_Wagner Questions? October 24th, 2018 Marquis Nob Hill C/DOracle Open World https://www.us-analytics.com/oac-active-directory-single-sign-on