How can users log in to IBM Cloud?

Today, authentication in IBM Cloud only works with an IBMid. If you create an IBM Cloud account, then you either already have an IBMid or you created one to open the account. Also, if you invite users to your IBM Cloud account, accepting the invitation creates an IBMid user (if they aren’t one already).

How does federation work with IBMid in IBM Cloud?

To relieve your enterprise employees from having to create and manage an IBMid user just for logging into IBM Cloud, there is an option available to onboard employees to IBMid. This way, your enterprise employees can log into IBMid with their usual intranet credentials. For more information about setting up enterprise federation with IBMid, check out the federation guide.

This IBMid federation option provides many benefits and is widely used by many of our enterprise customers.  Nevertheless, federation onboarding to IBMid is a manual process between you and the IBMid team. And, there are certain requirements—such as a worldwide unique email address—that can’t be met by all customers.

While the existing solution of IBMid federation is helpful for many and a popular option, IBM Cloud Identity and Access Management (IAM) is now offering another option.

Using an external identity provider to federate users in IBM Cloud

IBM Cloud IAM can now leverage the IBM Cloud App ID service to connect to external identity providers and allow those users to log into an IBM Cloud account. This way, any external identity provider that is supported by App ID can be leveraged. 

Some of the benefits of integrating your App ID instance with IBM Cloud IAM include self-service federation instead of completing a manual onboarding with IBMid and no restrictions on email addresses or usernames like there is with IBMid federation, which requires a worldwide unique email address.

Review the following high-level steps for integrating an external identity provider into your IBM Cloud account:

  1. If you don’t have one already, create an IBM Cloud account. This step does require you to create or use an existing IBMid.
  2. Create an instance of the App ID service from the IBM Cloud Catalog and configure it so it connects correctly to your external identity provider. Remember, any user that can authenticate through your App ID instance can access your IBM Cloud account, so only allow users who you want to be able to access your account.
  3. In the IBM Cloud console, go to Manage > Access (IAM), and then click Identity providers. Here, you can create an IAM Identity provider that points to the App ID instance from Step 2.
  4. Copy the login URL from this page and provide it to your employees when logging into IBM Cloud. If you have an employee portal or website, you can create a link using this login URL so that everybody can easily log into IBM Cloud.

Tip: To further automate the handling of IBM Cloud account users, you can create access groups with dynamic rules. Whenever a user logs in to IBM Cloud, those rules are evaluated and the user is potentially added to an access group that gives access to specific resources in IBM Cloud.

Check out the documentation to learn more about this exciting new feature in IBM Cloud.

More from Announcements

Success and recognition of IBM offerings in G2 Summer Reports  

2 min read - IBM offerings were featured in over 1,365 unique G2 reports, earning over 230 Leader badges across various categories.   This recognition is important to showcase our leading products and also to provide the unbiased validation our buyers seek. According to the 2024 G2 Software Buyer Behavior Report, “When researching software, buyers are most likely to trust information from people with similar roles and challenges, and they value transparency above other factors.”  With over 90 million visitors each year and hosting more than 2.6…

Manage the routing of your observability log and event data 

4 min read - Comprehensive environments include many sources of observable data to be aggregated and then analyzed for infrastructure and app performance management. Connecting and aggregating the data sources to observability tools need to be flexible. Some use cases might require all data to be aggregated into one common location while others have narrowed scope. Optimizing where observability data is processed enables businesses to maximize insights while managing to cost, compliance and data residency objectives.  As announced on 29 March 2024, IBM Cloud® released its next-gen observability…

Unify and share data across Netezza and watsonx.data for new generative AI applications

3 min read - In today's data and AI-driven world, organizations are generating vast amounts of data from various sources. The ability to extract value from AI initiatives relies heavily on the availability and quality of an enterprise's underlying data. In order to unlock the full potential of data for AI, organizations must be able to effectively navigate their complex IT landscapes across the hybrid cloud.   At this year’s IBM Think conference in Boston, we announced the new capabilities of IBM watsonx.data, an open…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters