My Oracle Support Banner

IDCS Federation with OpenIAM as IDP Getting Error (Doc ID 2541677.1)

Last updated on JUNE 24, 2019

Applies to:

Identity Cloud Service (IDCS) - Version N/A and later
Information in this document applies to any platform.


We have setup IDCS federation with our SAML SSO solution using OpenIAM as Identity Provider. After setup we are able to get properly redirected to our SSO login page,

but after login we are returned to IDCS and receive the following error:

 "Oracle Identity Cloud Service can't authenticate the user account. Contact your system administrator."


1. Setup using the same procedure for OAM as IDP as detailed in

2. Tested the connection through the IDCS administrative console and get:
Connection Failed. Configuration may need to be modified.
Cannot validate the following SAML assertion from partner OpenIAM

3. The SAML assertion itself indicates a Success status
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>


To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!

In this Document

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.