Hello Philippe,
I used to work for IBM Planning Analytics on Cloud (PAoC) Support.
Back then, I helped quite a many PAoC customers to federate authentication against AzureAD. These PAoC customers did not have to purchase or use an IBM service or software named "IBM Security Verify". IBM PAoC Support does not enable federate authentication. This is done by a specialised group, the IBMid Enterprise Federation team. As outlined by the IBM Federation Guide you have to open a support case and request federation of your PAoC environments. Quote:
"To begin this process, open a case at ibm.com/mysupport with Product, "IBMid Enterprise Federation" and state that you'd like to federate your Company IdP with IBMId." PAoC Support will act as your sponsor: They will forward you, respectively your AzureAD administrators, to the IBMid Enterprise Federation team. Afterwards your AzureAD administrators and the IBMid Enterprise Federation team will collaborate, by email and/or by webex sessions, to federate your PAoC environments.
Links:
https://www.ibm.com/docs/en/planning-analytics/2.0.0?topic=information-federated-authenticationIBM Planning Analytics with Watson / 2.0.0 / Getting Started / Planning Analytics on Cloud / Getting started with Planning Analytics on Cloud / Planning Analytics account and system information /
Federated authentication
Regards
------------------------------
Bernd Siebert
------------------------------
Original Message:
Sent: Fri October 14, 2022 03:21 AM
From: Philippe CHAMPLEBOUX
Subject: PA Cloud Authentication via Azure AD
Thanks a lot Peter,
I saw this documentation and missing about "create an Enterprise Application in azure AD".
(When authentication is federated to azure AD, we need to create an "entreprise application azure" not only for IBM but for all autentication system).
I think "www.ibm.com/docs/en/security-verify?topic=directory-configuring-azure-active-as-identity-provider" is a good begin but need some explanation about it and have an account on "IBM Security Verify".
I don't kow anything about this "IBM Security Verify" and I care about an supplementary licensing cost.
Do you think that IBM support hase th skill to answer and to detail all this methode ?
Best regards,
Philippe
------------------------------
Philippe CHAMPLEBOUX
Original Message:
Sent: Fri October 14, 2022 02:54 AM
From: Peter D'Haeyer
Subject: PA Cloud Authentication via Azure AD
Hi Philippe,
Standard authentication for PA on Cloud is IBMid. This can be federated to the local IDP, in your case Azure AD. Some more detailed information can be found here. All of this will be specified in the welcome kit and organised during the onboarding. Basically , you will have to specify the domain name ( as part of the IBMid email ) to be federated to your organisation.IBM Federation Guide https://ibm.ent.box.com/v/IBMid-Federation-Guide
Kind regards
Peter
------------------------------
Peter D'Haeyer
Original Message:
Sent: Thu October 13, 2022 01:35 PM
From: Philippe CHAMPLEBOUX
Subject: PA Cloud Authentication via Azure AD
Hello !
I prepare my organisation to migrate PA from on Premise to Cloud.
All seem to be quiet except My IT Chief want ours users be autenticate via Azure AD.
I read some article, notices, guide and it seem possible but I can't find some information .. how to do that.
Have you already do that ?
Can you share your experience or documentation ?
Bests regards,
Philippe
------------------------------
Philippe CHAMPLEBOUX
------------------------------
#PlanningAnalyticswithWatson