All Articles

CP4I Single Sign-On with Azure AD

I haven’t personally tested this (yet) but I think it’s important to have an outline of what it would entail to do this.

Goal

Use ADFS to authenticate against Cloud Pak for Integration using SAML.

Steps

In order to do this you must provide authentication and authorization to ADFS users. ADFS doesn’t support the LDAP protocol by default, however, Microsoft has a detailed document about leveraging “Azure AD Domain Services” to achieve LDAP authentication.

At a high level here are the steps that need to happen:

  1. Configure LDAP authentication with Azure Active Directory.
  2. Configure LDAP in the IBM Cloud Pak Platform UI
  3. Add users in the IBM Cloud Pak Platform UI
  4. Configure Single Sign-On against your ADFS.