Adaptive Insights

Before You Begin

Introduction

This document describes how to configure Oracle Identity Cloud Service to provide Single Sign-On (SSO) for Adaptive Insights using SAML.

About Adaptive Insights

Adaptive Insights offers a combined Business Intelligence (BI) and Corporate Performance Management (CPM) suite which is designed from the “cloud up” approach. The App offers designing, consolidation, analytics and reporting features which are capable yet instinctive for a wide range of business clients.

After integrating Adaptive Insights with Oracle Identity Cloud Service:

  • Users can access Adaptive Insights using their Oracle Identity Cloud Service login credentials.
  • Users can start Adaptive Insights using the Oracle Identity Cloud Service My Apps console.
  • Admins can assign and revoke user access to the Adaptive Insights app using the Oracle Identity Cloud Service administration console.

What Do You Need?

  • An Oracle Identity Cloud Service account with authorization rights to manage apps and users (Identity Domain Administrator or Application Administrator).
  • An Adaptive Insights account with authorization rights to configure federated authentication.
  • Make sure that the email ID of each user in Adaptive Insights matches the primary email ID of the Oracle Identity Cloud Service account.

Configuring the Adaptive Insights App in Oracle Identity Cloud Service

Use this section to register and activate the Adaptive Insights app, and then assign users to the app.

Prerequisite Steps

An account ID is required before you can register and activate the Adaptive Insights app. You obtain that account ID from Adaptive Insights.

  1. Access Adaptive Insights as an administrator using the URL: https://login.adaptiveinsights.com. The Adaptive Insights home page appears.

  2. Click the menu icon, and then click Administration.

  3. Click SAML SSO Settings.

The account ID appears in the Adaptive Insights SSO URL: https://login.adaptiveinsights.com/samlsso/<Account_ID>.

Registering and Activating the Adaptive Insights App

  1. Access the Oracle Identity Cloud Service administration console, select Applications, and then click Add.

  2. Click App Catalog.

  3. Search for Adaptive Insights, and then click Add.

  4. In the App Details section, enter your Adaptive Insights Account ID, and then click Next.

Note: This is the account ID that you obtained while performing the steps in the "Prerequisite Steps" section.

  1. Click Download Identity Provider Metadata.

    Tip: Use this file later during the Adaptive Insights configuration in the "Configuring SSO for Adaptive Insights" section.

  2. Click Download Signing Certificate.

    Tip: Use this file later during the Adaptive Insights configuration in the "Configuring SSO for Adaptive Insights" section.

  3. Click Finish. Oracle Identity Cloud Service displays a confirmation message.

  4. Click Activate, and then click Activate Application. Oracle Identity Cloud Service displays a confirmation message.

Assigning Users to the Adaptive Insights App

  1. On the Adaptive Insights app page in Oracle Identity Cloud Service, select Users, and then click Assign. The Assign Users window appears.

  2. Select users that you want to assign to Adaptive Insights, and then click OK. Oracle Identity Cloud Service displays a confirmation message stating that the Adaptive Insights app is assigned to the users that you selected.

    Note: The user account should be created on both Oracle Identity Cloud Service and Adaptive Insights for SSO.

Configuring SSO for Adaptive Insights

  1. Access Adaptive Insights as an administrator using the URL: https://login.adaptiveinsights.com. The Adaptive Insights home page appears.

  2. In the upper-left corner, click the menu icon, and then click Administration.

  3. On the Administration page, click SAML SSO Settings.

  4. Use the table to update the SAML SSO settings, and then click Save.

    Attribute Settings
    Identity provider name Enter IDCS.
    Identity provider Entity ID Enter the Identity provider Entity ID/Issuer URL. Use the metadata file that you downloaded earlier to obtain the Entity ID/Issuer URL. The Entity ID/Issuer URL information is located in the first line of the metadata. See the "Registering and Activating the Adaptive Insights App" section.
    Identity provider SSO URL Enter the Identity provider SSO URL: https://<IDCS-Service-Instance>.identity.oraclecloud.com/fed/v1/idp/sso.
    Identity provider certificate Click Browse, and then upload the signing certificate that you downloaded during Adaptive Insights registration in Oracle Identity Cloud Service. See the "Registering and Activating the Adaptive Insights App" section.
    SAML user id Select the User's Adaptive Insights user name radio button.
    SAML user id location Select the User id in NameID of Subject radio button. In the SAML NameID format field, select Email address from the drop-down list.
    Enable SAML Select the Allow SAML SSO and direct Adaptive Insights login radio button.

Verifying the Integration

Use this section to verify that SSO works when initiated from Oracle Identity Cloud Service (IdP Initiated SSO).

Verifying Identity Provider Initiated SSO from Oracle Identity Cloud Service

  1. Access the Oracle Identity Cloud Service My Profile console using the URL: https://<IDCS-Service-Instance>.identity.oraclecloud.com/ui/v1/myconsole.

  2. Log in using credentials for a user that is assigned to the Adaptive Insights app. Oracle Identity Cloud Service displays a shortcut to Adaptive Insights under My Apps.

  3. Click Adaptive Insights. The Adaptive Insights home page appears.

  4. Confirm that the user that is logged in is the same for both Adaptive Insights and Oracle Identity Cloud Service.

This confirms that SSO that is initiated from Oracle Identity Cloud Service works.

Troubleshooting

Use this section to locate solutions to common integration issues.

Known Issues

Adaptive Insights displays the message, "User with given credentials not found."

Cause: The email attribute sent by Oracle Identity Cloud Service during SSO doesn't match any existing user in Adaptive Insights.

Solution: Ensure that the user that you assign to the Adaptive Insights app has an account in both Oracle Identity Cloud Service and Adaptive Insights with the same email address.

Oracle Identity Cloud Service displays the message, “You are not authorized to access the app. Contact your system administrator."

Cause 1: The SAML 2.0 integration between the Oracle Identity Cloud Service Adaptive Insights app and Adaptive Insights is deactivated.

Solution 1:

  • Access the Oracle Identity Cloud Service administration console, select Applications, and then Adaptive Insights.
  • In the App Details section, click Activate, and then click Activate Application. Oracle Identity Cloud Service displays a confirmation message.

Cause 2: The administrator revokes access for the user at the same time that the user tries to access the Adaptive Insights app using Oracle Identity Cloud Service.

Solution 2:

  • Access the Oracle Identity Cloud Service administration console, select Applications, and then select Adaptive Insights.
  • In the App Details section, select Users, and then click Assign to re-assign the user.

Unknown Issues

For unknown issues, contact Oracle Support:

  1. Go to https://support.oracle.com.

  2. Select Cloud Support, and then sign in with your support credentials.

  3. In the Cloud Dashboard, confirm that there are no planned outages in Oracle Identity Cloud Service, and then click Create Service Request.

  4. Select Oracle Identity Cloud Service as the service type.

  5. Complete your service request.