Check the Logout Enabled box if logout needs to be enabled recommended.

Deploying Oracle Identity Federation 3-17 Integrate Oracle Identity Federation with Oracle Access Manager After processing an incoming SSO assertion and identifying the user, Oracle Identity Federation will create an Oracle Access Manager session for that user in the Oracle Access Manager domain. To do so, Oracle Identity Federation will: 1. Use a policy domain created by Oracle Identity Federation at configuration time. 2. Map the Oracle Identity Federation authentication mechanism, representing the authentication method used by the IdP to challenge the user, to an Oracle Access Manager authentication scheme that was created by Oracle Identity Federation at configuration time. If the mapped Oracle Access Manager authentication scheme does not exist, then Oracle Identity Federation will use the default authentication scheme entered in the Oracle Identity Federation configuration section 3. Interact with Oracle Access Manager to create the user session, by specifying the policy domain and the authentication scheme for that session The policy domain name that you enter for Oracle Identity Federation cannot reference an existing policy domain that was not created by Oracle Identity Federation. It must be created by Oracle Identity Federation. 4. Set the Oracle Access Manager cookie in the users browser For proper integration, Oracle Identity Federation needs to create policy objects and authentication schemes in Oracle Access Manager. Perform the following operations: Note: ■ The cookie domain must be set on the Webgate for the protected resource. An example of a cookie domain is: .us.oracle.com ■ You use Fusion Middleware Control to configure the user data store that Oracle Identity Federation uses when creating policy objects in the Oracle Access Manager Policy Server. If you change the user data store through Fusion Middleware Control: ■ redo the Oracle Identity FederationOracle Access Manager integration ■ update the existing authentication schemes that were created by Oracle Identity Federation in the Oracle Access Manager Policy Server. Note: This task assumes you have the appropriate administrator credentials for Oracle Access Manager. Ensure that the Oracle Access Manager Master Administrators account is used to create the policy objects. See Also: Oracle Fusion Middleware Administrators Guide for Oracle Access Manager 10g