Ask: Being logged into the S123 Field App should add a user to all appropriate SAML groups on the Portal
Overly long explanation: Had an odd issue today where a user couldn't submit a form. I eventually checked the sharing group, and they weren't added to the corporate "ALLCOMPANY" group which should contain 100% of employees.
This is a SAML group in the Portal which I updated a few days ago to point to a different group in our AD. As a result, all users were kicked out of the old group (not a concern).
As new users logged into the Portal to use web maps, they were added to the updated SAML group (cool. It's working).
But this one user was only logging in via the S123 Field App (I'm sure they would need other services eventually, but I'm a little thankful they didn't in this case). Apparently being logged in to the Field App doesn't sync up with the server in such a way as to re-add a user to SAML groups, thus creating odd security scenarios like this one.
They could...
- Log into and access S123 Field App
- Download locked forms
They could not...
- Submit to locked forms as they weren't in the proper group (not an issue on it's own - I just want SAML groups to do their thing).