Identity Cloud Service and SAML

Identity Cloud Service or IDCS provides Identity Management capabilities hosted in the Cloud to Oracle customers, including:

This article covers the SAML features supported by IDCS 17.2.2 and later.

SAML Support

Protocol

The following SAML 2.0 protocols and bindings are supported by IDCS:

Cryptography

The IDCS SAML service supports the following cryptographic features:

SAML Assertion Generation

As an IdP, IDCS supports the following when issuing a SAML 2.0 Assertion

SAML Assertion Consumption

As an SP, IDCS validates the incoming SAML Assertion and map it to an IDCS user record. The service supports the following:

Endpoints

The services implementing the SAML 2.0 protocol are published at:

The SAML service also provides two endpoints to initiate a Federation SSO operation, ignoring whether or not the user is already authenticated at the target SP domain. As a consequence, these flows should not be primarily used, and instead the user should be sent to the target SSO service which determines whether or not an authentication involving Federation SSO is required. Both SAML services (IdP or SP) support starting a Federation SSO:

More Learning Resources

Explore other labs on docs.oracle.com/learn or access more free learning content on the Oracle Learning YouTube channel. Additionally, visit education.oracle.com/learning-explorer to become an Oracle Learning Explorer.

For product documentation, visit Oracle Help Center.