SlideShare una empresa de Scribd logo
1 de 30
Descargar para leer sin conexión
Becky Wagner, Sr BI Architect
E: bwagner@us-analytics.com T: @Bec_Wagner
Active Directory and Single Sign-On
with Oracle Analytics Cloud (OAC)
October 24th, 2018 Oracle Open World Marquis Nob Hill C/D
https://www.us-analytics.com/oac-active-directory-single-sign-on
2
AGENDA
OAC Options – Customer Case1
AD Bridge2
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
3
BECKY WAGNER
WHO AM I?
§ Wife; Mother of 3 (ages 16, 13, and 9);
§ 2nd degree black belt in Tae Kwon Do
§ Red Cross Blood Drive Coordinator
§ ODTUG BI Community Leader
§ Oracle ACE Associate
§ Sr BI Architect at US-Analytics
§ 14 years in IT
§ Email: bwagner@us-analytics.com
§ Twitter: @Bec_Wagner
§ LinkedIn: https://www.linkedin.com/in/rebecca-wagner-bb356924/
§ IRC Channel (Telegram): #obihackers
3 Membership Tiers
• Oracle ACE Director
• Oracle ACE
• Oracle ACE Associate
bit.ly/OracleACEProgram
500+ Technical Experts
Helping Peers Globally
Connect:
Nominate yourself or someone you know: acenomination.oracle.com
@oracleace
Facebook.com/oracleaces
oracle-ace_ww@oracle.com
7
Who is US-Analytics?
80+
EPM and BI
professionals
with 12+ years of experience.
BY THE NUMBERS
19+years in business
with continued growth
>600clients
1,500+engagements
with
8
TECHNOLOGYENERGY FINANCIAL RETAIILHEALTHCARE
Sampling of EPM Clients (Project and Support) Approx. 100 Projects Annually
9
AGENDA
OAC Options – Customer Case1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
AD Bridge2
10
• Security is highest priority
• Waited to start Project until AD integration
• VPNaaS to Palo Alto NextGen Firewalls
• Private IP Ranges
• Access from within network only
• OAC with IDCS (Identity Cloud)
• Migrating from OBIEE 11g to OAC
• AD integration required (8000+ users, 14000+
groups)
• SSO was highly desirable
Large Financial Management Customer
US-Analytics: Customer Case – Enterprise worthy OAC
11
AGENDA
OAC Options – Customer Case1
AD Bridge2
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
12
AD Bridge
Besides following the tutorial, what you need:
• Must install on Server joined to AD Domain
• User with rights to install software
• User with the following AD rights
• Read for all users and groups in the domain
• Read for all OUs
• If you are using an AD user specifically setup for this AD Bridge, specific permissions
can be found here:
• https://docs.oracle.com/en/cloud/paas/identity-cloud/uaids/creating-
bridge.html
• Tutorial for AD Bridge
• https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs
_idbridge_obe/idbridge.html
13
AD Bridge - Roadmap
1. Download From IDCS
2. Install On Domain-Joined Server
3. Configure Users and Groups
4. Import in IDCS
5. Verify
*Note: OAC comes with IDCS Foundation. AD Bridge is in IDCS Basic.
14
AD Bridge – Detailed Steps Part 1
• Browser - IDCS, navigate to Directory Integration and click Add
• Copy the URL, Client ID and Client Secret
• Click Download
• Click Run and Next, Next, Next
• Enter the URL, ID and Secret and Test
• If successful, click Next
• Enter AD Domain User and Password and Test
• If successful, click Next
1:07
1:15
1:52
1:55
2:12
2:21
2:27
2:31
15
AD Bridge – Detailed Steps Part 2
• Browser – IDCS Directory Integration partially configured
• Expand OU’s and check appropriate OU for Users
• Repeat for groups
• Click Attribute Mappings, delete all non-needed, don’t change
• Save, Refresh, Import
• Verify by clicking on Users tab in left menu
3:07
3:17
3:25
3:32
4:17
5:01
16
AD Bridge, Video Walk-Through
https://youtu.be/QbQV-riohVI
17
AD Bridge – The More You Know
• Becomes a service. Note that this service is running and starts automatically
• Find the AD Bridge Config Utility in C:Program FilesIDBridgeIDBridgeUI.exe
• Click on View Logs – Highly important to note log locations
• Sync has a limit, will continue at the frequency until fully sync’d
• Errors will have details in the logs, like missing email or some other attribute issue
18
AGENDA
OAC Options1
Direct SSO vs Link4
Trouble Spots5
SAML 2.0 ADFS3
AD Bridge2
19
ADFS & Single Sign-On – SAML 101
Img from - https://developers.onelogin.com/assets/img/pages/saml/sso-diagram.svg
20
ADFS & Single Sign-On – Detailed Steps Part 1
1. Download ADFS Metadata File
• https://adfs.contoso.com/FederationMetadata/2007-06/FederationMetatdata.xml
• XML files have tags, if browser doesn’t show them, right click and view source, then save
2. IDCS Identity Provider Setup
• Add SAML IDP
• Name, Next, Upload FederationMetadata.xml, Requested NameID – Email Addr, Next, Finish
• Don’t click Export – Use the following URL to download IDCS metadata XML
• https://MYTENANT.identity.oraclecloud.com/fed/v1/metadata?adfsmode=true
Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html
0:23
1:40
21
ADFS & Single Sign-On – Detailed Steps Part 2
3. In AD FS management console add a Relying Party Trust
• Import Metadata.xml, Next, Name, Next Next Next Next, Finish
• Add Claim Rules
1. Send LDAP Attributes as Claims, Name - Email, Attribute Store - Active Directory,
LDAP Attribute - Email Addresses and Outgoing Claim Type – Email Address
2. Transform an Incoming Claim, Name – Name ID, Incoming – Email Address,
Outgoing claim – Name ID, Outgoing format – Email
4. IDCS Configuration
• Drop down – select Activate, Drop down again – select Show on Login Page
• IDP Policies – Click Default and then Assign new ADFS
Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html
2:43
4:20
22
ADFS & Single Sign-On, Video Walk-Through
https://youtu.be/FcULyV0mgFs
23
AGENDA
OAC Options1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
2 AD Bridge
24
Removing Local Logins
Oracle Support Doc ID 2438952.1
OAC/OAAC: How To Disable IDCS Chooser Login Page and Get Redirected to Custom SSO
Login Page Directly in Oracle Analytics Cloud(OAC)
Once everything has been confirmed working for SSO link on login page:
• IDP Policies
• Remove ADFS from ‘Default Identity Provider Policy’
• Create new IDP Policy
• Assign ADFS to Policy
• Assign OAC Application(s)
• Configure Application for Redirect URL
• Can be any URL (www.oracle.com), and doesn’t actually affect behavior
0:12
0:26
1:05
25
Removing Local Logins, Video Walk-Through
https://youtu.be/Hg5EKV2nmnM
26
AGENDA
OAC Options1
SAML 2.0 ADFS3
Direct SSO vs Link4
Trouble Spots5
2 AD Bridge
27
Things to be on the lookout for
Trouble Spots and Lessons Learned
ADFS Direct SSOAD Bridge
• Sometimes logs stop
while still showing
Active in IDCS and
service shows
running in Windows
• Logs path not in
documentation, use
ADBridge Application
and View Logs.
• While checking OUs,
be sure to expand
and check lower
levels (Default now)
• Username - Email
• IDCS uses SAML 2.0,
for Win 2016 we had
to get a different
ADFS xml file
• Don’t download the
Export IDCS
metadata. ADFS
needs a special
format. Can get from
URL:
• https://DOMAIN.oracle
cloud.com/fed/v1/met
adata?adfsmode=true
• Security wants users
to be authenticated
by AD only
• EM, RPD Admin Tool,
Weblogic Console,
still direct login –
Can’t use AD users
• Configure IDP Policy
• Sign Out redirects to
OAC DV, still signed
in. Can configure
ADFS global sign-out
then IDCS sign out
URL
28
11g Migration User Folder name change
Account Rename
29
§ Remove IDCS Chooser Page
§ Still need local login for EM
and Weblogic Console and RPD
Admin Tool
RECAP
OAC Options AD Bridge
SAML 2.0 ADFS Direct SSO or Link
§ Security Sensitive
§ IDCS Private IP
§ Allows for AD and SSO
integration
§ Local AD Domain joined Server
§ Find your logs
§ Find your ADFS buddy
§ Sign Out – redirects to DV
§ Claim Rules only worked with
Email
Getting Fancy: HA AD Bridge – Docker style
https://www.oracle.com/technetwork/articles/idm/gutierrez-idcs-idbridge-3960710.html
Becky Wagner, Sr BI Architect
E: bwagner@us-analytics.com T: @Bec_Wagner
Questions?
October 24th, 2018 Marquis Nob Hill C/DOracle Open World
https://www.us-analytics.com/oac-active-directory-single-sign-on

Más contenido relacionado

La actualidad más candente

Amazon AWS & IAAS
Amazon AWS & IAASAmazon AWS & IAAS
Amazon AWS & IAASDivyang Oza
 
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020Timothy McAliley
 
Load balancing
Load balancingLoad balancing
Load balancingSoujanya V
 
introduction-to-cloud-computing
introduction-to-cloud-computingintroduction-to-cloud-computing
introduction-to-cloud-computingssuserc27607
 
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...Majid Hajibaba
 
Microsoft Azure Cloud Services
Microsoft Azure Cloud ServicesMicrosoft Azure Cloud Services
Microsoft Azure Cloud ServicesDavid J Rosenthal
 
Cloud computing
Cloud computingCloud computing
Cloud computingstudent
 
The Layman's Guide to Microsoft Azure
The Layman's Guide to Microsoft AzureThe Layman's Guide to Microsoft Azure
The Layman's Guide to Microsoft AzureAptera Inc
 
Load Balancing in Cloud
Load Balancing in CloudLoad Balancing in Cloud
Load Balancing in CloudMphasis
 
Cloud computing
Cloud computingCloud computing
Cloud computingkanchu17
 
Data Lakehouse, Data Mesh, and Data Fabric (r2)
Data Lakehouse, Data Mesh, and Data Fabric (r2)Data Lakehouse, Data Mesh, and Data Fabric (r2)
Data Lakehouse, Data Mesh, and Data Fabric (r2)James Serra
 
Migrating your Data Centre to AWS
Migrating your Data Centre to AWSMigrating your Data Centre to AWS
Migrating your Data Centre to AWSAmazon Web Services
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to AzureRobert Crane
 
Windows Azure Virtual Machines
Windows Azure Virtual MachinesWindows Azure Virtual Machines
Windows Azure Virtual MachinesClint Edmonson
 
Oracle Cloud Infrastructure.pptx
Oracle Cloud Infrastructure.pptxOracle Cloud Infrastructure.pptx
Oracle Cloud Infrastructure.pptxGarvitNTT
 
Introducing Azure SQL Database
Introducing Azure SQL DatabaseIntroducing Azure SQL Database
Introducing Azure SQL DatabaseJames Serra
 

La actualidad más candente (20)

Amazon AWS & IAAS
Amazon AWS & IAASAmazon AWS & IAAS
Amazon AWS & IAAS
 
Microsoft azure
Microsoft azureMicrosoft azure
Microsoft azure
 
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020
Data Migration to Azure SQL and Azure SQL Managed Instance - June 19 2020
 
Load balancing
Load balancingLoad balancing
Load balancing
 
introduction-to-cloud-computing
introduction-to-cloud-computingintroduction-to-cloud-computing
introduction-to-cloud-computing
 
Mobile cloud computing.pptx
Mobile cloud computing.pptxMobile cloud computing.pptx
Mobile cloud computing.pptx
 
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...
Cloud Computing Principles and Paradigms: 7 enhancing cloud computing environ...
 
Microsoft Azure Cloud Services
Microsoft Azure Cloud ServicesMicrosoft Azure Cloud Services
Microsoft Azure Cloud Services
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
The Layman's Guide to Microsoft Azure
The Layman's Guide to Microsoft AzureThe Layman's Guide to Microsoft Azure
The Layman's Guide to Microsoft Azure
 
Load Balancing in Cloud
Load Balancing in CloudLoad Balancing in Cloud
Load Balancing in Cloud
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Data Lakehouse, Data Mesh, and Data Fabric (r2)
Data Lakehouse, Data Mesh, and Data Fabric (r2)Data Lakehouse, Data Mesh, and Data Fabric (r2)
Data Lakehouse, Data Mesh, and Data Fabric (r2)
 
Migrating your Data Centre to AWS
Migrating your Data Centre to AWSMigrating your Data Centre to AWS
Migrating your Data Centre to AWS
 
Introduction to Azure
Introduction to AzureIntroduction to Azure
Introduction to Azure
 
Windows Azure Virtual Machines
Windows Azure Virtual MachinesWindows Azure Virtual Machines
Windows Azure Virtual Machines
 
Oracle Cloud Infrastructure.pptx
Oracle Cloud Infrastructure.pptxOracle Cloud Infrastructure.pptx
Oracle Cloud Infrastructure.pptx
 
Introducing Azure SQL Database
Introducing Azure SQL DatabaseIntroducing Azure SQL Database
Introducing Azure SQL Database
 
Graph database
Graph database Graph database
Graph database
 
Mobile cloud computing
Mobile cloud computingMobile cloud computing
Mobile cloud computing
 

Similar a AD SSO with Oracle Analytics Cloud - Oracle Open World 18

20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic way20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic waymakker_nl
 
O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365NCCOMMS
 
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)TIMETOACT GROUP
 
Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365InnoTech
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision IT
 
Forge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with ForgeForge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with ForgeAutodesk
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureSparkhound Inc.
 
From desktop to the cloud with forge
From desktop to the cloud with forgeFrom desktop to the cloud with forge
From desktop to the cloud with forgefpm2015
 
Fusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons LearnedFusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons LearnedAndrejs Karpovs
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity managementDavid Pechon
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAnthony Clendenen
 
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision IT
 
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...Tomasz Poszytek
 
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure ADBlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure ADBlueHat Security Conference
 
RightScale Webinar: Get Your App To Azure
RightScale Webinar:  Get Your App To AzureRightScale Webinar:  Get Your App To Azure
RightScale Webinar: Get Your App To AzureRightScale
 
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environmentDEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environmentFelipe Prado
 
Using Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management ChallengesUsing Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management ChallengesMichael Collier
 
CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018Robert Crane
 
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise DirectoryCause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise Directoryrwgorrel
 

Similar a AD SSO with Oracle Analytics Cloud - Oracle Open World 18 (20)

20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic way20180605 sso with apex and adfs the weblogic way
20180605 sso with apex and adfs the weblogic way
 
O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365O365Engage17 - Identity in the cloud foundation for o365
O365Engage17 - Identity in the cloud foundation for o365
 
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
Integrate Applications into IBM Connections Cloud and On Premises (AD 1632)
 
Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365
 
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
 
Forge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with ForgeForge - DevCon 2016: From Desktop to the Cloud with Forge
Forge - DevCon 2016: From Desktop to the Cloud with Forge
 
Identity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft AzureIdentity Management for Office 365 and Microsoft Azure
Identity Management for Office 365 and Microsoft Azure
 
From desktop to the cloud with forge
From desktop to the cloud with forgeFrom desktop to the cloud with forge
From desktop to the cloud with forge
 
Fusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons LearnedFusion Applications Bare Metal Provisioning - Lessons Learned
Fusion Applications Bare Metal Provisioning - Lessons Learned
 
O365-AzureAD Identity management
O365-AzureAD Identity managementO365-AzureAD Identity management
O365-AzureAD Identity management
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD Deployment
 
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365Envision it SharePoint Extranet Webinar Series - Federation and Office 365
Envision it SharePoint Extranet Webinar Series - Federation and Office 365
 
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
[PU&D] Why the Microsoft 365 Administrator should care about the Power Platfo...
 
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure ADBlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
BlueHat Seattle 2019 || I'm in your cloud: A year of hacking Azure AD
 
RightScale Webinar: Get Your App To Azure
RightScale Webinar:  Get Your App To AzureRightScale Webinar:  Get Your App To Azure
RightScale Webinar: Get Your App To Azure
 
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
AMIS Oracle OpenWorld 2015 Review – part 3- PaaS Database, Integration, Ident...
 
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environmentDEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
DEF CON 27 - DIRK JAN MOLLEMA - im in your cloud pwning your azure environment
 
Using Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management ChallengesUsing Windows Azure for Solving Identity Management Challenges
Using Windows Azure for Solving Identity Management Challenges
 
CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018CIAOPS Need to Know Azure Webinar - January 2018
CIAOPS Need to Know Azure Webinar - January 2018
 
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise DirectoryCause 2013: A Flexible Approach to Creating an Enterprise Directory
Cause 2013: A Flexible Approach to Creating an Enterprise Directory
 

Último

Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sectoritnewsafrica
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesThousandEyes
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...Jeffrey Haguewood
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integrationmarketing932765
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessWSO2
 
Infrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsInfrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsYoss Cohen
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...Karmanjay Verma
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
Digital Tools & AI in Career Development
Digital Tools & AI in Career DevelopmentDigital Tools & AI in Career Development
Digital Tools & AI in Career DevelopmentMahmoud Rabie
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...panagenda
 
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...JET Technology Labs White Paper for Virtualized Security and Encryption Techn...
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...amber724300
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 

Último (20)

Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...
Email Marketing Automation for Bonterra Impact Management (fka Social Solutio...
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with Platformless
 
Infrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsInfrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platforms
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
Digital Tools & AI in Career Development
Digital Tools & AI in Career DevelopmentDigital Tools & AI in Career Development
Digital Tools & AI in Career Development
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
 
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...JET Technology Labs White Paper for Virtualized Security and Encryption Techn...
JET Technology Labs White Paper for Virtualized Security and Encryption Techn...
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 

AD SSO with Oracle Analytics Cloud - Oracle Open World 18

  • 1. Becky Wagner, Sr BI Architect E: bwagner@us-analytics.com T: @Bec_Wagner Active Directory and Single Sign-On with Oracle Analytics Cloud (OAC) October 24th, 2018 Oracle Open World Marquis Nob Hill C/D https://www.us-analytics.com/oac-active-directory-single-sign-on
  • 2. 2 AGENDA OAC Options – Customer Case1 AD Bridge2 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5
  • 3. 3 BECKY WAGNER WHO AM I? § Wife; Mother of 3 (ages 16, 13, and 9); § 2nd degree black belt in Tae Kwon Do § Red Cross Blood Drive Coordinator § ODTUG BI Community Leader § Oracle ACE Associate § Sr BI Architect at US-Analytics § 14 years in IT § Email: bwagner@us-analytics.com § Twitter: @Bec_Wagner § LinkedIn: https://www.linkedin.com/in/rebecca-wagner-bb356924/ § IRC Channel (Telegram): #obihackers
  • 4.
  • 5.
  • 6. 3 Membership Tiers • Oracle ACE Director • Oracle ACE • Oracle ACE Associate bit.ly/OracleACEProgram 500+ Technical Experts Helping Peers Globally Connect: Nominate yourself or someone you know: acenomination.oracle.com @oracleace Facebook.com/oracleaces oracle-ace_ww@oracle.com
  • 7. 7 Who is US-Analytics? 80+ EPM and BI professionals with 12+ years of experience. BY THE NUMBERS 19+years in business with continued growth >600clients 1,500+engagements with
  • 8. 8 TECHNOLOGYENERGY FINANCIAL RETAIILHEALTHCARE Sampling of EPM Clients (Project and Support) Approx. 100 Projects Annually
  • 9. 9 AGENDA OAC Options – Customer Case1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 AD Bridge2
  • 10. 10 • Security is highest priority • Waited to start Project until AD integration • VPNaaS to Palo Alto NextGen Firewalls • Private IP Ranges • Access from within network only • OAC with IDCS (Identity Cloud) • Migrating from OBIEE 11g to OAC • AD integration required (8000+ users, 14000+ groups) • SSO was highly desirable Large Financial Management Customer US-Analytics: Customer Case – Enterprise worthy OAC
  • 11. 11 AGENDA OAC Options – Customer Case1 AD Bridge2 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5
  • 12. 12 AD Bridge Besides following the tutorial, what you need: • Must install on Server joined to AD Domain • User with rights to install software • User with the following AD rights • Read for all users and groups in the domain • Read for all OUs • If you are using an AD user specifically setup for this AD Bridge, specific permissions can be found here: • https://docs.oracle.com/en/cloud/paas/identity-cloud/uaids/creating- bridge.html • Tutorial for AD Bridge • https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs _idbridge_obe/idbridge.html
  • 13. 13 AD Bridge - Roadmap 1. Download From IDCS 2. Install On Domain-Joined Server 3. Configure Users and Groups 4. Import in IDCS 5. Verify *Note: OAC comes with IDCS Foundation. AD Bridge is in IDCS Basic.
  • 14. 14 AD Bridge – Detailed Steps Part 1 • Browser - IDCS, navigate to Directory Integration and click Add • Copy the URL, Client ID and Client Secret • Click Download • Click Run and Next, Next, Next • Enter the URL, ID and Secret and Test • If successful, click Next • Enter AD Domain User and Password and Test • If successful, click Next 1:07 1:15 1:52 1:55 2:12 2:21 2:27 2:31
  • 15. 15 AD Bridge – Detailed Steps Part 2 • Browser – IDCS Directory Integration partially configured • Expand OU’s and check appropriate OU for Users • Repeat for groups • Click Attribute Mappings, delete all non-needed, don’t change • Save, Refresh, Import • Verify by clicking on Users tab in left menu 3:07 3:17 3:25 3:32 4:17 5:01
  • 16. 16 AD Bridge, Video Walk-Through https://youtu.be/QbQV-riohVI
  • 17. 17 AD Bridge – The More You Know • Becomes a service. Note that this service is running and starts automatically • Find the AD Bridge Config Utility in C:Program FilesIDBridgeIDBridgeUI.exe • Click on View Logs – Highly important to note log locations • Sync has a limit, will continue at the frequency until fully sync’d • Errors will have details in the logs, like missing email or some other attribute issue
  • 18. 18 AGENDA OAC Options1 Direct SSO vs Link4 Trouble Spots5 SAML 2.0 ADFS3 AD Bridge2
  • 19. 19 ADFS & Single Sign-On – SAML 101 Img from - https://developers.onelogin.com/assets/img/pages/saml/sso-diagram.svg
  • 20. 20 ADFS & Single Sign-On – Detailed Steps Part 1 1. Download ADFS Metadata File • https://adfs.contoso.com/FederationMetadata/2007-06/FederationMetatdata.xml • XML files have tags, if browser doesn’t show them, right click and view source, then save 2. IDCS Identity Provider Setup • Add SAML IDP • Name, Next, Upload FederationMetadata.xml, Requested NameID – Email Addr, Next, Finish • Don’t click Export – Use the following URL to download IDCS metadata XML • https://MYTENANT.identity.oraclecloud.com/fed/v1/metadata?adfsmode=true Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html 0:23 1:40
  • 21. 21 ADFS & Single Sign-On – Detailed Steps Part 2 3. In AD FS management console add a Relying Party Trust • Import Metadata.xml, Next, Name, Next Next Next Next, Finish • Add Claim Rules 1. Send LDAP Attributes as Claims, Name - Email, Attribute Store - Active Directory, LDAP Attribute - Email Addresses and Outgoing Claim Type – Email Address 2. Transform an Incoming Claim, Name – Name ID, Incoming – Email Address, Outgoing claim – Name ID, Outgoing format – Email 4. IDCS Configuration • Drop down – select Activate, Drop down again – select Show on Login Page • IDP Policies – Click Default and then Assign new ADFS Tutorial: https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/idcs/idcs_adfs_obe/adfs.html 2:43 4:20
  • 22. 22 ADFS & Single Sign-On, Video Walk-Through https://youtu.be/FcULyV0mgFs
  • 23. 23 AGENDA OAC Options1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 2 AD Bridge
  • 24. 24 Removing Local Logins Oracle Support Doc ID 2438952.1 OAC/OAAC: How To Disable IDCS Chooser Login Page and Get Redirected to Custom SSO Login Page Directly in Oracle Analytics Cloud(OAC) Once everything has been confirmed working for SSO link on login page: • IDP Policies • Remove ADFS from ‘Default Identity Provider Policy’ • Create new IDP Policy • Assign ADFS to Policy • Assign OAC Application(s) • Configure Application for Redirect URL • Can be any URL (www.oracle.com), and doesn’t actually affect behavior 0:12 0:26 1:05
  • 25. 25 Removing Local Logins, Video Walk-Through https://youtu.be/Hg5EKV2nmnM
  • 26. 26 AGENDA OAC Options1 SAML 2.0 ADFS3 Direct SSO vs Link4 Trouble Spots5 2 AD Bridge
  • 27. 27 Things to be on the lookout for Trouble Spots and Lessons Learned ADFS Direct SSOAD Bridge • Sometimes logs stop while still showing Active in IDCS and service shows running in Windows • Logs path not in documentation, use ADBridge Application and View Logs. • While checking OUs, be sure to expand and check lower levels (Default now) • Username - Email • IDCS uses SAML 2.0, for Win 2016 we had to get a different ADFS xml file • Don’t download the Export IDCS metadata. ADFS needs a special format. Can get from URL: • https://DOMAIN.oracle cloud.com/fed/v1/met adata?adfsmode=true • Security wants users to be authenticated by AD only • EM, RPD Admin Tool, Weblogic Console, still direct login – Can’t use AD users • Configure IDP Policy • Sign Out redirects to OAC DV, still signed in. Can configure ADFS global sign-out then IDCS sign out URL
  • 28. 28 11g Migration User Folder name change Account Rename
  • 29. 29 § Remove IDCS Chooser Page § Still need local login for EM and Weblogic Console and RPD Admin Tool RECAP OAC Options AD Bridge SAML 2.0 ADFS Direct SSO or Link § Security Sensitive § IDCS Private IP § Allows for AD and SSO integration § Local AD Domain joined Server § Find your logs § Find your ADFS buddy § Sign Out – redirects to DV § Claim Rules only worked with Email Getting Fancy: HA AD Bridge – Docker style https://www.oracle.com/technetwork/articles/idm/gutierrez-idcs-idbridge-3960710.html
  • 30. Becky Wagner, Sr BI Architect E: bwagner@us-analytics.com T: @Bec_Wagner Questions? October 24th, 2018 Marquis Nob Hill C/DOracle Open World https://www.us-analytics.com/oac-active-directory-single-sign-on