The image shows an external IdP federation source comprising an IdP user group and a separate group. The IdP federation source access an OCI AIM group membership within an EU Sovereign Cloud tenancy. This group also contains local user A. Another A separate local user A exists within the tenancy. External to the tenancy, an IdP user authenticates through the EU Sovereign Cloud tenancy to access the IdP federation source and local user A authenticates into the tenancy.