Creating an Identity Store for Account Linking

When defining an identity provider partner record, the service provider requires local user accounts to be mapped for imposing its access control model. The process of mapping SAML user accounts from the IdP to the local user accounts at the service provider is known as account linking. In this case, external user accounts that are authenticated by the identity provider need to be mapped to generic local user accounts with permission to access resources.

To create an identity store for account linking:

  1. In the Launch Pad tab, under Federation, click Service Provider Management.
  2. In the Service Provider Administration tab, click Create Identity Provider Partner and then complete the following:
    1. In the Name field, enter a name (for example, FederationStore) for the identity provider partner.
    2. In the User Identity Store menu, under User Mapping, select the name of the identity store that you used to configure SSO.
    3. In the relevant fields, enter the information that you recorded from the identity store earlier.
    4. Click Apply.
  3. (Optional) Enable automatic user provisioning for the local identity store used by service providers by completing the tasks in Enabling Automatic User Provisioning for the Local Identity Store used by Service Providers.

Related Topics

Configuring Oracle Access Manager for Federated Identity Using SAML 2.0

Enabling Automatic User Provisioning for the Local Identity Store used by Service Providers

Enabling Identity Federation

Creating an Identity Provider Partner

Exporting SAML 2.0 Service Provider Metadata

Creating a SAML Authentication Policy

Assigning an Authentication Policy to Application Resources



Legal Notices | Your Privacy Rights
Copyright © 1999, 2024

Last Published Thursday, February 29, 2024