Enable Single Sign-On (SSO) Login for Inbound Microsoft Teams or Slack Client Connectors

From release 26D, you can use Single Sign-On (SSO) login for your inbound Microsoft Teams or Slack client connectors in the following scenarios:

  • If you want your users to use one organizational identity to securely access these connectors, rather than maintaining separate credentials for each system.
  • If your user's email addresses do not match their Azure or Slack email addresses.

Backward Compatibility

  • SSO is optional. Existing Microsoft Teams and Slack instances can continue to use the current authentication mechanism without enabling SSO.
  • You do not need to recreate an existing instance to enable SSO. To enable SSO, update the instance with the IDCS Client ID and Client Secret, and enable the corresponding SSO profile option.
  • When you enable SSO for an existing instance, users with an established session are not required to sign in again immediately. Their current session remains active until it expires, which is currently approximately two weeks. After the session expires, the SSO sign-in flow is triggered.
  • You can disable SSO after enabling it without affecting the existing instance. After you disable the SSO profile option, users no longer receive the SSO sign-in prompt, and the integration reverts to the previous authentication behavior.
  • The IDCS Client ID and Client Secret can remain configured on the instance when SSO is disabled. The ORA_FAI_EXTERNAL_TOOLS_ENABLE_SSO profile option determines whether the SSO flow is active.

To enable SSO:

Create an IDCS Client

To enable the SSO feature, you'll need to create a Confidential Application within the Oracle Cloud Console. This Confidential Application will provide the OAuth credentials that will be used by your Microsoft Teams or Slack client connectors.

Sign in to the Oracle Cloud Console to create a Confidential Application in your Oracle Identity Cloud Service instance.

  1. Sign in to the Oracle Cloud Console.
  2. Navigate to Identity & Security > Identity Domains.
  3. Select the Domain listed as the "Current Domain".
  4. Click the Integration Applications tab.
  5. Click Add application.
  6. Select Confidential Application and click Launch workflow.
  7. Enter a Name and click Submit.
  8. Click the OAuth Configuration tab.
  9. Click Edit OAuth Configuration.
    1. In Resource server configuration, select No resource server configuration.
    2. In Client Configuration:
      • Select Configure this application as a client now.
      • In Allowed grant types, select Client credentials and Authorization code.
    3. In Redirect URL, enter https://<fusion-domain>/api/fusion-ai/orchestrator/collabTools/v1/sso-redirect-url where <fusion-domain> is the name of your Fusion domain.
    4. In Client type, select Confidential.
    5. In the Certificate section:
      • For Allowed operations, select Introspect.
      • Enable Bypass consent.
      • In Client IP Address, select Anywhere.
    6. In the Token issuance policy section:
      • In Authorized resources, select All.
      • Enable Add resources.
    7. In Resources, ensure that you add the required scopes, for example:
      • Oracle Boss Cloud (Spectra) - urn:opc:resource:fusion<fusion-domain>:boss/
      • Oracle RWDTOOLS Spectra Cloud - urn:opc:resource:fusion<fusion-domain>:rwdtools/
      • Fusion Applications Cloud Service - urn:opc:resource:faaas:fa:<fusion-domain-urn>:opc:resource:consumer::all/
      • Oracle Fusion AI Cloud (Spectra) - urn:opc:resource:fusion<fusion-domain>:fusion-ai/
  10. Click the Groups tab, and assign a user defined Fusion job role, for example Employee. Make sure that all the required users are a part of that Fusion job role. You can also add multiple groups.
  11. Click Submit.
  12. Select Activate in the Actions menu and Activate application.
  13. From the OAuth configuration section, copy the values for the Client ID and Client secret. These values will be used to configure your Microsoft Teams or Slack client connectors.
Note: You must ensure that synchronization and provisioning is enabled for Fusion Application Cloud Service. This is required to automatically synchronize users with IDCS whenever a new user is added in Fusion Cloud to the configured Fusion role or group. For more information, refer Enable Provisioning and Synchronization.

Create or Update the Connector in AI Agent Studio with IDCS Credentials

  1. In AI Agent Studio, click the Connectors tab.
  2. Under Configured connectors, click the existing Team or Slack client connector.
  3. Under Bot Configuration, update the IDCS Client ID and IDCS Client Secret.
  4. Click Update.

For more information, see:

Enable the SSO Profile Option

  1. Go to Setup and Maintenance, click the Tasks icon, and click Search.
  2. Search and select Manage Administrator Profile Values.
  3. In the Profile Option Code field, enter ORA_FAI_EXTERNAL_TOOLS_ENABLE_SSO and click Search.
  4. For the Site profile level, select the profile value as Yes.
  5. Click Save and Close.
Note: This profile option applies to all Slack and Microsoft Teams instances, including multiple instances of each, within the same pod.