Legacy App SSO · Oracle E-Business Suite
Oracle E-Business Suite SSO with Keycloak
We connect EBS to Keycloak through the integration paths Oracle supports, so users reach forms and self-service pages with one login and MFA — including their existing Entra ID, Okta or Active Directory credentials — without touching EBS application code.
- Integrates via EBS Asserter or OAM
- MFA before users reach EBS
- FND_USER accounts linked, not rebuilt
Standards & integrations
- SAML 2.0
- OpenID Connect
- EBS Asserter
- Oracle Access Manager
- OCI IAM identity domains
- Oracle WebLogic
Overview
Why EBS SSO needs more than a SAML checkbox
E-Business Suite doesn't accept a SAML assertion or OIDC token from an external identity provider on its own. Oracle's documented routes run through its own components: the EBS Asserter, a lightweight application on WebLogic that trusts an OCI IAM identity domain and creates the EBS session, or Oracle Access Manager, where WebGate protects EBS and EBS AccessGate maps the signed-in user to an EBS session. We place Keycloak in front of either as the identity provider your users actually sign in to, map every identity to the right FND_USER account, and keep session behaviour predictable for forms and self-service users alike.
What we deliver
- Integration design for your EBS release and topology
- Keycloak realm with an MFA policy for ERP users
- SAML federation between Keycloak and the Oracle integration component
- FND_USER account linking and reconciliation report
- Logout and session-timeout alignment tested end to end
- Cut-over runbook with break-glass and rollback steps
Capabilities
What Oracle E-Business Suite covers
Configured, tested and documented on upstream Keycloak — then handed over or operated by us.
Oracle-supported integration path
We integrate through the EBS Asserter or Oracle Access Manager with EBS AccessGate rather than patching EBS, so the setup stays within the routes Oracle documents.
Sign in with Entra ID, Okta or AD
Keycloak is the front door with your password policy, MFA and passkeys, and brokers Microsoft Entra ID, Okta or Active Directory so users keep the credentials they have.
Account linking to FND_USER
Each identity maps to its existing FND_USER record by username or email, with mismatches found and fixed before go-live instead of on the help desk.
MFA on every entry point
Forms, self-service and the EBS home page all go through the same Keycloak login, and the local EBS login page is restricted to break-glass use.
Aligned logout and timeouts
Sign-out from EBS ends the Keycloak session too, and idle timeouts are aligned so users aren't caught between two different session clocks.
Directory alignment
If Oracle Internet Directory or Active Directory holds your users today, it stays the source of user data and is federated into Keycloak.
Compatibility
EBS integration paths
Which route we use depends on your release and the Oracle components you already run. Every row is confirmed against Oracle's certification notes for your version.
| Platform | Integration | Notes |
|---|---|---|
| EBS 12.2 with an OCI IAM identity domain | EBS Asserter + SAML 2.0 federation to Keycloak | Oracle's current route for cloud identity; the identity domain trusts Keycloak as an external IdP. |
| EBS 12.2 with Oracle Access Manager | OAM + WebGate + EBS AccessGate, OAM federated to Keycloak | Fits estates already running OAM; uses OAM identity federation over SAML 2.0. |
| EBS 12.1.3 | Oracle-certified component for your release | Component support differs from 12.2 — confirmed against Oracle's certification notes before design. |
| Microsoft Entra ID, Okta or AD users | Brokered through Keycloak | Users keep their existing credentials; EBS still trusts one supported chain. |
| Oracle Internet Directory users | LDAP federation into Keycloak | OID remains the source of user data during and after migration. |
| Forms and self-service pages | Same SSO session | Both are covered once the login entry point is switched. |
How it works
From first call to production
Assess your release and topology
We confirm the EBS version, patch levels, WebLogic and any existing SSO components, then pick the supported path — EBS Asserter or Access Manager — that fits.
Build the chain on a clone
Keycloak, the Oracle integration component and user linking are set up on a cloned instance and tested for forms, self-service, logout and timeouts.
Cut over with a fallback
Users move to the new login in a planned window, with the local login page kept for break-glass access and a documented rollback.
Use cases
Where teams put it to work
Retiring ageing Oracle SSO
Replace old Oracle single sign-on and access-manager infrastructure with a supported path and a modern identity provider in front of it.
One login across Oracle and SaaS
Finance and operations staff use the same credentials and MFA for EBS as for their SaaS tools and internal applications.
MFA for ERP access
Put phishing-resistant MFA in front of EBS for security and audit requirements without changing EBS code.
FAQ
Oracle E-Business Suite questions, answered
Does Oracle EBS support SAML or OIDC natively?
Not directly. EBS doesn't accept a SAML assertion or OIDC token from an external identity provider by itself; Oracle's documented routes use the EBS Asserter with an OCI IAM identity domain, or Oracle Access Manager with WebGate and EBS AccessGate. Keycloak federates to either over SAML 2.0.
Do we need Oracle Access Manager and OID for EBS SSO?
Not necessarily. The EBS Asserter route uses an OCI IAM identity domain instead of OAM and OID, and that identity domain trusts Keycloak. If you already run OAM, we can keep it and federate it to Keycloak instead.
What's the difference between the EBS Asserter and OAM with AccessGate?
The EBS Asserter is a lightweight application on WebLogic that receives the user's identity from an OCI IAM identity domain and creates the EBS session. The OAM route puts WebGate in front of EBS and uses EBS AccessGate to turn the authenticated user into an EBS session — which means running and patching the OAM stack.
Can users sign in to EBS with Microsoft Entra ID or Okta?
Yes. Keycloak brokers Entra ID, Okta or Active Directory sign-ins, so users keep the credentials they already have while EBS trusts a single, supported chain.
Which EBS versions can you work with?
EBS 12.2 is the main target. For 12.1.3 we confirm which components Oracle certifies for your exact release and patch level during the assessment.
Will users lose their responsibilities or history?
No. Users keep their existing FND_USER accounts, responsibilities and history. SSO only changes how they prove who they are — we link identities to the accounts that already exist.
Ready to roll out Oracle E-Business Suite?
Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.