<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Multiple SAML logins within both ArcGIS Enterprise and AGOL environments in ArcGIS Enterprise Ideas</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-ideas/multiple-saml-logins-within-both-arcgis-enterprise/idi-p/1638692</link>
    <description>&lt;P&gt;We administer both ArcGIS Enterprise (11.4) and ArcGIS Online environments, supporting hundreds of users from federal, state, and local government agencies.&lt;/P&gt;&lt;P&gt;Currently, we're facing challenges due to the use of different authentication services. Our setup utilises SAML authentication tied to the federal agency’s identity provider, which leaves state and local agencies reliant on built-in ArcGIS accounts.&lt;/P&gt;&lt;P&gt;This reliance on built-in accounts has led to considerable administrative overhead, particularly when enforcing multi-factor authentication (MFA), which requires disabling and re-enabling accounts. Additionally, there's an ongoing security concern: when users depart their agencies, we aren’t consistently notified, leading to accounts remaining active and unauthorized access lingering.&lt;/P&gt;&lt;P&gt;We’re curious to know if others have encountered similar issues, and whether any alternative workflows have helped streamline identity management in comparable multi-agency environments.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Aug 2025 00:55:37 GMT</pubDate>
    <dc:creator>MichelleAlley</dc:creator>
    <dc:date>2025-08-06T00:55:37Z</dc:date>
    <item>
      <title>Multiple SAML logins within both ArcGIS Enterprise and AGOL environments</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/multiple-saml-logins-within-both-arcgis-enterprise/idi-p/1638692</link>
      <description>&lt;P&gt;We administer both ArcGIS Enterprise (11.4) and ArcGIS Online environments, supporting hundreds of users from federal, state, and local government agencies.&lt;/P&gt;&lt;P&gt;Currently, we're facing challenges due to the use of different authentication services. Our setup utilises SAML authentication tied to the federal agency’s identity provider, which leaves state and local agencies reliant on built-in ArcGIS accounts.&lt;/P&gt;&lt;P&gt;This reliance on built-in accounts has led to considerable administrative overhead, particularly when enforcing multi-factor authentication (MFA), which requires disabling and re-enabling accounts. Additionally, there's an ongoing security concern: when users depart their agencies, we aren’t consistently notified, leading to accounts remaining active and unauthorized access lingering.&lt;/P&gt;&lt;P&gt;We’re curious to know if others have encountered similar issues, and whether any alternative workflows have helped streamline identity management in comparable multi-agency environments.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 00:55:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/multiple-saml-logins-within-both-arcgis-enterprise/idi-p/1638692</guid>
      <dc:creator>MichelleAlley</dc:creator>
      <dc:date>2025-08-06T00:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple SAML logins within both ArcGIS Enterprise and AGOL environments</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/multiple-saml-logins-within-both-arcgis-enterprise/idc-p/1638768#M4296</link>
      <description>&lt;P&gt;I know some people utilising &lt;A href="https://www.keycloak.org/" target="_blank"&gt;Keycloak&lt;/A&gt; as unified login page.&lt;/P&gt;&lt;P&gt;When a user attempts to log in, they hit Keycloak’s login page. Keycloak routes them to their respective agency IdP, based on a login hint, email domain, or user selection. Once authenticated upstream, Keycloak asserts the user’s identity to ArcGIS.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 13:17:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/multiple-saml-logins-within-both-arcgis-enterprise/idc-p/1638768#M4296</guid>
      <dc:creator>SimonSchütte_ct</dc:creator>
      <dc:date>2025-08-04T13:17:51Z</dc:date>
    </item>
  </channel>
</rss>

