Federation guidelines

Keep the following guidelines in mind when using a federated account with Oracle Life Sciences IAMS.

Federation account linking

Some Oracle Life Sciences products, such as Oracle InForm, support federation with third-party identity providers, such as Exostar. To use federation, you must link your identity provider account with your Oracle Life Sciences IAMS account. For specific information on how to use federation with your product, see your product documentation.

Oracle Life Sciences IAMS supports Security Assertion Markup Language (SAML) federation between a customer identity provider (IDP) and Identity Cloud Service (IDCS) for use in Oracle Clinical One Platform.

Access control

  • If you cannot access Oracle Life Sciences Cloud using your identity provider, you can sign in to Oracle systems directly using your Oracle Life Sciences SSO credentials.
  • User accounts created through Oracle IDCS continue to receive Oracle Life Sciences IAMS new account and password expiration notification emails. Contact your Oracle Services lead to disable these notification emails.

Session security

  • When signing out of Oracle Life Sciences Cloud, close your browser to ensure all sign-in sessions end. You may be signed in to Oracle in multiple browser windows or tabs. Signing out in one browser window does not sign you out of all browser windows. Closing all open browsers ensures all sign-in sessions end.
  • Your Oracle Life Sciences IAMS session can time out while your identity provider session is still active. Your system-wide session timeout is defined by your identity provider.
  • The re-authentication period for your Oracle Life Sciences SSO session may be extended when you have an active identity provider session. Because the identity provider re-authentication time exceeds the Oracle Life Sciences IAMS time limit, someone may be able to sign in again on your computer without re-entering your sign-in credentials even after the Oracle Life Sciences IAMS timeout period. Your authentication period is extended to the authentication period defined by your identity provider when an identity provider session is in use. You can avoid this extension by closing your browser after signing out.

Electronic signatures

If you have signed in to Oracle Life Sciences Cloud using your identity provider credentials, the system requires you to re-authenticate using those same credentials for electronic signature.

When users are authenticated through federation with Oracle Identity Cloud Service (IDCS), they can eSign a document in an application using IDCS credentials.