Planning Analytics

Planning Analytics

Get AI-infused integrated business planning

 View Only
  • 1.  PA Cloud Authentication via Azure AD

    Posted Thu October 13, 2022 02:48 PM
    Hello !

    I prepare my organisation to migrate PA from on Premise to Cloud.

    All seem to be quiet except  My IT Chief want  ours users be autenticate via Azure AD.

    I read some article, notices, guide and it seem possible but I can't find some information .. how to do that.

    Have you already do that ?
    Can you share your experience or documentation ?

    Bests regards,
    Philippe


    ------------------------------
    Philippe CHAMPLEBOUX
    ------------------------------

    #PlanningAnalyticswithWatson


  • 2.  RE: PA Cloud Authentication via Azure AD

    Posted Fri October 14, 2022 02:55 AM
    Hi Philippe,

    Standard authentication for PA on Cloud is IBMid. This can be federated to the local IDP, in your case Azure AD. Some more detailed information can be found here. All of this will be specified in the welcome kit and organised during the onboarding. Basically , you will have to specify the domain name ( as part of the IBMid email ) to be federated to your organisation.

    IBM Federation Guide https://ibm.ent.box.com/v/IBMid-Federation-Guide

    Kind regards 

    Peter



    ------------------------------
    Peter D'Haeyer
    ------------------------------



  • 3.  RE: PA Cloud Authentication via Azure AD

    Posted Fri October 14, 2022 03:21 AM
    Thanks a lot Peter,

    I saw this documentation and missing about "create an Enterprise Application in azure AD".
    (When authentication is federated to azure AD, we need to create an "entreprise application azure" not only for IBM but for all autentication system).


    I think "www.ibm.com/docs/en/security-verify?topic=directory-configuring-azure-active-as-identity-provider" is a good begin but need some explanation about it and have an account on "IBM Security Verify".
    I don't kow anything about this "IBM Security Verify" and I care about an supplementary licensing cost.

    Do you think that IBM support hase th skill to answer and to detail all this methode ?
    Best regards,
    Philippe


    ------------------------------
    Philippe CHAMPLEBOUX
    ------------------------------



  • 4.  RE: PA Cloud Authentication via Azure AD

    Posted Fri October 14, 2022 06:38 AM
    Hello Philippe,

    I used to work for IBM Planning Analytics on Cloud (PAoC) Support.

    Back then, I helped quite a many PAoC customers to federate authentication against AzureAD. These PAoC customers did not have to purchase or use an IBM service or software named "IBM Security Verify".  IBM PAoC Support does not enable federate authentication. This is done by a specialised group, the IBMid Enterprise Federation team. As outlined by the IBM Federation Guide you have to open a support case and request federation of your PAoC environments. Quote: "To begin this process, open a case at ibm.com/mysupport with Product, "IBMid Enterprise Federation" and state that you'd like to federate your Company IdP with IBMId."  PAoC Support will act as your sponsor: They will forward you, respectively your AzureAD administrators, to the IBMid Enterprise Federation team. Afterwards your AzureAD administrators and the IBMid Enterprise Federation team will collaborate, by email and/or by webex sessions, to federate your PAoC environments.


    Links:

    https://www.ibm.com/docs/en/planning-analytics/2.0.0?topic=information-federated-authentication
    IBM Planning Analytics with Watson / 2.0.0 / Getting Started / Planning Analytics on Cloud / Getting started with Planning Analytics on Cloud / Planning Analytics account and system information /
    Federated authentication


    Regards

    ------------------------------
    Bernd Siebert
    ------------------------------



  • 5.  RE: PA Cloud Authentication via Azure AD

    Posted Fri October 14, 2022 09:34 AM
    Bernd,

    Thanks a lot, I am now totally quiet  about this authentication.

    A lot of thanks !

    Best regards,
    Philippe

    ------------------------------
    Philippe CHAMPLEBOUX
    ------------------------------