Configure SAML single sign-on (SSO) in IDMC to exchange authentication and authorization information with your identity provider.
Tip:
To watch a video that describes the SAML configuration procedure, see https://youtu.be/4DewSNbvJBc?si=VAeGj5-5Oq0HbXtF.
SAML single sign-on requires an identity provider and service provider. Examples of identity providers include: Okta, Microsoft Azure AD, and PingFederate. In this scenario, the service provider is IDMC.
Before you can configure SAML SSO in IDMC, it must already be set up in your identity provider. For information about configuring two common identity providers, see the following articles on the Informatica network:
1Contact your identity provider team for the following information:
- Issuer
- Single Sign-on Service URL
- Signing Certificate
2Enter the information into the corresponding fields in Identity Provider Configuration section of the SAML Setup page:
- Issuer
- Single Sign-on Service URL
- Signing Certificate
The following images shows these fields on the SAML Setup page:
3Enter the Name Identifier Format if possible, otherwise this can be added later. The following image shows the Name Identifier Format field:
4Click Save.
IDMC generates the service provider metadata file and a unique token for your organization.
5Click Download Service Provider Metadata. This downloads the file iics_saml_sp_metadata.xml to your machine. It contains information that your service provider needs to complete the configuration.
6In the Information dialog box, note the URL for single sign-on access to your IDMC organization. For example:
If there isn't a matching IDMC group, enter a new group name and IDMC will create this group and map it to the SAML group. Groups created this way are read-only in IDMC.
12If you don't want to map specific groups and instead just use a default group, perform the following steps:
aEnsure that Map SAML Groups and Roles is not selected.
bIn the SAML Group Mapping tab, scroll to the bottom of the list and select a Default Group.
The Administrator can change the groups later.
13Complete the remaining fields on the SAML Setup page as necessary. For more information, see SAML configuration.