# Step 5: Configure Oracle Business Intelligence Enterprise Edition (OBIEE) for Single Sign-On (SSO)

### 1. Enable WebLogic Plug-In Support

#### 1.1 Access the WebLogic Admin Console

* Go to:\
  [**http://test.public.myvcn.oraclevcn.com:9500/console**](http://test.public.myvcn.oraclevcn.com:9500/console)
* Log in with WebLogic administrator credentials.

#### 1.2 Enable WebLogic Plug-In

* Navigate to:\
  **Domain Structure > Clusters > bi\_cluster**
* Click **"Lock & Edit"**
* Scroll to the **Advanced** section and enable **"WebLogic Plug-In"**
* Click **Save**, then **Activate Changes**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXe5EHakD3dnucrhYPJtoJl6BGl9Q3Kn3svwfIxSWlgr8UMp77klAkQxYki59uXgRLa6ddtyxUwUrMkDXYLIJF3HZexSUwHTD6dx5iSIpydrgmTDjXiIvD6l8kvuBc7uu-7E-qM2dg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### 2. Configure Authentication Providers in WebLogic

#### 2.1 Navigate to Security Realms

* Go to:\
  **Domain Structure > Security Realms > myrealm > Providers**
* Click **"Lock & Edit"**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcnYQs0p9F9ZvnftQktn6QeXDvSXHrsynM79j9jlrNJ_1DAtGIfVunjJ3TlzxU_mnSr6rHeFGAZxdkCAE2nZTBB6dz_unWn-59OJ2NzDskc2rTggAHlRGQKLlgYo6DUeHU8ulaXXw?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

#### 2.2 Add Authentication Providers

* Add:
  * `OIDAuthenticator`
  * `SAMLAuthenticator`
* Reorder them accordingly.
* Click **"Activate Changes"**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdxAcEWA270Sd6rqyxN2MNc3tNNhdmTTAl8t468Fut_rM6DjBRXdWda1Jx6Wk8JDVSsiGrpBdoRSVm6Gk7AM2M8_dBvrGhF0sY_qkiqIs3dMINYR2ECUjowSiuGS5gPCJThDfX1fg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXd9QBqTCJfnaKnsl75Yzha4ljatfpZNKsPXBxjwa1SP2Sxll2fRNi9oTRWnhFwcapXWwl4BFKn91bmufAdS5BbJzIOGFNATsmFrQ6Yh1nlb10CrU1dkW5VGONULH5gfJBasInaxqA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcZRU-fxyTLoT__wxCwXQgaeIxvEJq1LZeZkdX34VEYnPHfuwAMB2s-DV_Zdk35YXgoa4wEdcAJ9_8PURwDSnV9vxOeFGZ95JEFHkXEVWHHpJeGs-Huj28aBsrziIq3qHcsAyOBpQ?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdn_4druzs65-P-PAEIPivbADjZlOLLNp_PDhhHPQ9EkSEqiIQsxCSf19WCnGl0Ac5ROGMVLK7Rt97eigCqelwK-Kw0Og7IUA0tWqQZURnhVPuKtBb-x0B4TK8tzaaL6VDq9KlA?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### 3. Configure OBIEE in Enterprise Manager

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdrQybliuPLIbTyZzk_rvyGOFUo3Cl-bAG_5xJ5x0IeMLM5Df5pIOEuJhidTTQGDl9tlbYCM9ymLeKRHXbQq1eKQ1T8I912nFk4yOtN8rGxHUjOPtKHi6mWq2OdKqqthz-jhFnBXg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

#### 3.1 Access OBIEE Enterprise Manager

* Go to:\
  **<http://test.public.myvcn.oraclevcn.com:9500/em>**

#### 3.2 Enable Identity Store Virtualization

* Navigate to:\
  **WebLogic Domain > Security > Security Provider Configuration > Identity Store Provider**
* Click **Configure**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeGwZ3AjXLu6em1XLnAaOHw3dfeIYq74-CERvS-F9O420OjVcSeYm2eGw2DkQnI0ZqsuRh1cIpJNxQawBIc-Low9d0Cb0SeQbVMMGypYVTOvCHYtz1d7xKwf_dT8MEGnxK_y4MnEg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

* Add property:

  ```
  virtualize = true
  ```

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdBzjmvKqv8w2tt6aTwsmvN1t_c7GFC-KCcxFjCdswi1IX7mpjkR9YVY1EAf3eYl46MQfA_Ld8TQ2IXAwfOxm9W46pIDQJKHXdV6UqeAD9vU-Ae57XLzBPDj21Se7Z1Bgcda8Bx?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### 4. Configure SSO Logoff URL

#### 4.1 Open the Security Tab

* Navigate to:\
  **Business Intelligence > coreapplication > Security**
* Click **"Lock & Edit"**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcQ3XEBJxZuB-EqvFd6k81R919kB5Py3mdcfrCRmN-c01ZWZbB7BJfpt1rNDeLE9XXZQLhEwt8giAmPVsdC38bS--lQZOcIrvYVpPJYw0dFknlktApPCCH_89o-FnM3cXK2XKpg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

#### 4.2 Add Logoff URL

* Enter:

  ```
  https://<your-environment>.savantage.net:14101/oam/server/logout
  ```
* Click **Apply**, then **Activate Changes**

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdqfrAn-AtOw3OsVBFFGJhfdhEFOMwJ4QCe0jKU2oDsEP6NNePr7a90SOL_FR7rkMf0IcZO3k07fqcuP61blWs5qS5jD-LnqPLoC-L_x4fUSt0HmEuFc8XdT5rgKk6mHnlHwIRgyw?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

***

### 5. Configure SSO in BI Publisher

#### 5.1 Access BI Publisher

* Go to:\
  **<http://test.public.myvcn.oraclevcn.com:9502/xmlpserver>**

#### 5.2 Enable Single Sign-On

* Navigate to:\
  **Administration > Authentication**
* Enable:
  * **Use Single Sign-On**
  * **Oracle Access Manager** as SSO Type
* Set logoff URL:

  ```
  https://test.public.myvcn.oraclevcn.com:14101/oam/server/logout
  ```
* Save changes

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc-25oFeCW1OLd7q5Sqq4Ou4uSU0hBlaWEEhePT0LSoN2BjjdeNG4SmOxMB8sfK5m1KvEmRRq206f6hSsxtj3C4k81wq24ovw5PGsypd-88umpZ1kvwSDbDD2MdWflZuqhOkewCgg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### 6. Restart OBIEE

* Restart the OBIEE domain to apply configuration changes.
* Confirm that all services restart successfully.

### 7. Map OID Groups to OBIEE Application Roles

#### 7.1 Access Role Mapping

* Go to:\
  **Enterprise Manager > Business Intelligence > coreapplication > Security > Application Roles**

#### 7.2 Assign Groups

* Map groups from Oracle Internet Directory (OID) to roles:

  * `OIDBIConsumers` → BIConsumer
  * `OIDBIContentAuthors` → BIAuthor
  * `OIDBIServiceAdministrator` → BIAdministrator

  <figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXc7kxDGiTCk5V2pPi5OR4a_7mtPhn5QrMBDbPnPnOg6U6XmjMXEXK8_tluqaVAhP1ZDG5zXOuLoatk6IrVZzQFSYJBNct55ZjAI5rJhb6evGZltN8iyMI-ppKOnpmholKdT3R0DCg?key=flYwr8QHc9296S5s6V_SpI0A" alt=""><figcaption></figcaption></figure>

### 8. Test the SSO Integration

* Access:\
  [**http://test.public.myvcn.oraclevcn.com:7777/analytics**](http://test.public.myvcn.oraclevcn.com:7777/analytics)
* You should be redirected to the OAM login page.
* After successful login, OBIEE should open with the appropriate access.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://enterprise.hideez.com/hideez-server-integration/saml-integration/oracle-business-intelligence-enterprise-edition-obiee/step-5-configure-oracle-business-intelligence-enterprise-edition-obiee-for-single-sign-on-sso.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
