<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea OpenID Connect group membership in ArcGIS Enterprise Ideas</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idi-p/1233952</link>
    <description>&lt;P&gt;SAML identity providers integrated with ArcGIS Enterprise can support group membership. Similarly, it would be great to support OIDC backed group membership through calls to a groups or memberOf (etc) property.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2022 22:29:25 GMT</pubDate>
    <dc:creator>AngusHooper1</dc:creator>
    <dc:date>2022-11-21T22:29:25Z</dc:date>
    <item>
      <title>OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idi-p/1233952</link>
      <description>&lt;P&gt;SAML identity providers integrated with ArcGIS Enterprise can support group membership. Similarly, it would be great to support OIDC backed group membership through calls to a groups or memberOf (etc) property.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 22:29:25 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idi-p/1233952</guid>
      <dc:creator>AngusHooper1</dc:creator>
      <dc:date>2022-11-21T22:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1234023#M3053</link>
      <description>&lt;P&gt;Even this is NOT a part nor compliance with current OIDC standard scopes / claims, this is feature that has been asked from several ArcGIS clients. Adding support for custom or enhanced scopes / claims like groups would be very helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 09:20:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1234023#M3053</guid>
      <dc:creator>sodtom</dc:creator>
      <dc:date>2022-11-22T09:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1235831#M3060</link>
      <description>&lt;P&gt;+1 !&lt;/P&gt;&lt;P&gt;As it is does not seem to be standard to OIDC protocol (correct me if I am wrong, not an expert !), a &lt;STRONG&gt;configurable &lt;/STRONG&gt;claim (aka not hardcoded) would be very useful to retrieve groups membership experience of SAML !&lt;/P&gt;&lt;P&gt;Thanks for listening&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 11:51:22 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1235831#M3060</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2022-11-29T11:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1321700#M3422</link>
      <description>&lt;P&gt;Voicing my support for this feature too! This would be tremendously helpful as we do this with a lot of other vendors already. It allows our cloud SA's to manage groups in our Azure tenant which will map them all to the appropriate group in the ESRI world.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 15:39:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1321700#M3422</guid>
      <dc:creator>jmp601</dc:creator>
      <dc:date>2023-08-23T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1330507#M3480</link>
      <description>&lt;P&gt;We would be interested in OpenID Connect, but will stay with SAML as long as group memberships are not available.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 07:50:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1330507#M3480</guid>
      <dc:creator>Martin1</dc:creator>
      <dc:date>2023-09-20T07:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership - Status changed to: Implemented</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1537780#M3897</link>
      <description>&lt;P&gt;Thank you for your Idea! This is now implemented in ArcGIS Enterprise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 14:36:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1537780#M3897</guid>
      <dc:creator>MaggieBusek</dc:creator>
      <dc:date>2024-09-12T14:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1537826#M3898</link>
      <description>&lt;P&gt;Fantastic news &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/549088"&gt;@MaggieBusek&lt;/a&gt; ! Thanks for listening.&lt;/P&gt;&lt;P&gt;Does that mean that it will be available at 11.4 ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 15:45:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1537826#M3898</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2024-09-12T15:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543205#M3924</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/408959"&gt;@NicolasGIS&lt;/a&gt;&amp;nbsp;This was implemented in Enterprise 11.3!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 20:09:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543205#M3924</guid>
      <dc:creator>MaggieBusek</dc:creator>
      <dc:date>2024-09-26T20:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543260#M3925</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/549088"&gt;@MaggieBusek&lt;/a&gt;&amp;nbsp;can you link to the documentation that outlines how to configure this? Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 23:39:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543260#M3925</guid>
      <dc:creator>AngusHooper1</dc:creator>
      <dc:date>2024-09-26T23:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543644#M3928</link>
      <description>&lt;P&gt;True, it does not seem to be documented yet for ArcGIS Enteprise but it is for ArcGIS Online:&lt;BR /&gt;&lt;A href="https://doc.arcgis.com/en/arcgis-online/administer/openid-connect-logins.htm" target="_blank" rel="noopener"&gt;https://doc.arcgis.com/en/arcgis-online/administer/openid-connect-logins.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Step 15:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Optionally, toggle the &lt;SPAN class=""&gt;Enable OpenID Connect login based group membership&lt;/SPAN&gt; button to allow members to link specified &lt;SPAN class=""&gt;OpenID Connect&lt;/SPAN&gt;-based groups to &lt;SPAN class=""&gt;ArcGIS Online&lt;/SPAN&gt; groups during the &lt;A href="https://doc.arcgis.com/en/arcgis-online/share-maps/create-groups.htm" target="_blank" rel="noopener"&gt;group creation process&lt;/A&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This step is missing from ArcGIS Enterprise 11.3 documentation:&lt;/P&gt;&lt;P&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm" target="_blank" rel="noopener"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But running 11.3, I confirm I do see the same option as in ArcGIS Online.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 10:10:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1543644#M3928</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2024-10-04T10:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1545506#M3934</link>
      <description>&lt;P&gt;From my first testing, I faced an issue with header size since I activated it. I don't know why, but Portal for ArcGIS is setting this "oidcRelayState" cookie on "signin" last operation:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;`sharing/rest/oauth2/oidc/xyz/signin`&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;and in my case, after having turn this OIDC group membership, it turns out that this cookie is massive and my header is greater than 40 KB afterward and got rejected by HAProxy. I increased the header size limit and it now works but it seems to me that my groups are stored in this cookie which is not a good practice according to my IT team. Any idea why are the groups stored in this cookie at the end of the auth process ? It seems to me this cookie is much more than a 'classic' relayState and also there is no state to manage at this stage as interaction with IDP is over&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Might open a dedicated thread rather than polluting this implemented idea !&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 11:32:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1545506#M3934</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2024-10-04T11:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: OpenID Connect group membership</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1565707#M4028</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/289569"&gt;@AngusHooper1&lt;/a&gt;&amp;nbsp; We document support for OIDC groups &lt;A href="https://enterprise.arcgis.com/en/portal/latest/use/create-groups.htm#:~:text=Connect%20group%E2%80%94-,Membership,-is%20controlled%20by" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/408959"&gt;@NicolasGIS&lt;/a&gt;&amp;nbsp;Thank you for noting that we don't include this information on the documentation page you linked. We will work to update that page to reflect this change.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your other feedback, if you wouldn't mind creating a dedicated thread that would be great. Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 17:23:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/openid-connect-group-membership/idc-p/1565707#M4028</guid>
      <dc:creator>MaggieBusek</dc:creator>
      <dc:date>2024-12-06T17:23:38Z</dc:date>
    </item>
  </channel>
</rss>

