Key to successful cloning of instances with SSO?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2025 05:07 AM
Hi everyone,
I need your advice, as I struggle with cloning Full PROD over SSO/MFA enabled TEST instance for my customer.
I've read a lot of materials, KB articles and official documentation, but it still does not manage to retain multi-factor authentication working on the target, resulting in such messages:
I used the following documentation as reference:
- Data preservation on cloning target instances
- Clone an instance with a SAML integration
- Checklist before cloning an instance with Digest / SSO / SAML / Multi SSO Integration to prevent den...
- Users not able to login in cloned target instance using Multi Factor Authentication (MFA) - Support ...
- Exclude a table from cloning
Based on these, I have modified my Profile's list of Preserves and Excludes (I can paste both in a comment later). However, I do not know if this list if comprehensive. I also could not find any recommendation regarding the cleanup scripts, so I included them all.
In any case, I do have a number of questions:
- Should I preserve sys_user and related table - partially (maybe keep an admin user) or all?
- What tables should I include as Preserves and Excludes?
- What clean-up scripts shall I include in the profile?
- Do you have an experience with cloning over a SSO enabled instance? What was your approach?
Thank you all in advance for the support!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2025 07:50 AM - edited 10-02-2025 07:54 AM
I have never had an issue with this. It looks like the table for multi-factor are already setup in the preserve data. If you are using clone profiles you may want to make sure they are still part of the preservations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2025 08:31 AM
Hi Brain,
Thank you for the suggestion, I need to add 2 of those tables to the next attempt. Do you also preserve the roles on the target instance?
Do you use a Profile (such as OOTB System) or do you request without? TBH I created a Profile, because that was the overall advice on the tutorials and I do not know an easier way to pick and choose which preserves/excludes will be included in the requested clone.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2025 08:37 AM
I do have clone profiles come over but everything is setup like the OOTB system except for some cleanup script I wrote that are not related to multi-factor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2025 09:21 AM
So, if I create a new profile, the OOTB settings will automatically be populated, correct? And on top of that I should just make sure that the MFA-related tables you mentioned earlier are all associated to this new profile?
