White Papers

Dell EMC OpenManage Enterprise Login with PingFederate
Dell EMC OpenManage Enterprise Login with PingFederate | 454
2 OME and PingFederate Configurations
This section describes the configuration required to enable user authentication in PingFederate.
2.1 Configure Scope and Policy in PingFederate
To enable OpenManage Enterprise OpenID Connect login using PingFederate, you must add and map a
scope dxcua to the Client ID and define the user privileges. The Dell Extended Claim for User Authentication
(dxcua) is necessary to identify the user roles and permissions required to manage OME.
To configure dxcua claim in PingFederate, do the following:
1. Log into PingFederate with administrative privileges.
2. Navigate to System->OAuth Settings->Scope Management->Exclusive Scopes
3. Set Scope Value to dxcua and Scope Description to Dell Extended Claim for User
Authentication as shown below in Figure 1.
Figure 1 PingFederate: Scope Management
After defining the dxcua scope, it is required to map dxcua to the PingFederate Policy.
To map “dxcua” scope to PingFederate Policy, do the following:
1. Navigate to Applications -> OpenID Connect Policy Management-> Select Policy-> Manage
Policy tab.
2. Select the INCLUDE USER INFO IN ID TOKEN check box as shown in Figure 2.