We've recently deployed Portal 10.4.1 and we have decided to use ADFS authentication as it works across all the apps we want to use (Collector, Survey123, ArcMap, ArcGIS Pro and browser). When you launch one of these applications the ADFS authentication looks for users with the following usernames: "username". However, when I use the built in tool to "add members based on existing enterprise users" then select "from a group" usernames are automatically generated as username@DOMAIN. These don't line up so users cannot login.
I have explored the "add members for <identity provider name> enterprise logins via SAML" and from here I can specify the username but I also have to enter the name and email address for each user either individually or in a file. This would require I look up each user individually and introduce an opportunity for typos.
Is there a way to pull new users in without the @DOMAIN added to their username? Alternatively, is there a way to change what the ADFS authentication is looking for so it can understand username@DOMAIN? What are other enterprise implementations doing?
Thanks,
Heather