The cloud platform supports identity federation with Security Assertion Markup Language (SAML), which is an open standard that many identity providers (IdPs) use. During identity federation, the cloud platform functions as a service provider (SP) and enterprises function as IdPs. This section describes how to configure identity federation and how identity federation works.
Ensure that your enterprise IdP supports SAML 2.0.
The following describes how to configure your enterprise IdP and the cloud platform to trust each other.
Figure 5 shows the identity federation process between an enterprise management system and the cloud platform.
To view interactive requests and assertions with a better experience, you are advised to use Google Chrome and install SAML Message Decoder.
As shown in Figure 5, the process of identity federation is as follows:
The assertion must carry a signature; otherwise, the login will fail.