<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Converting authentication from unique ArcGIS online users to Enterprise Azure AD users in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1160376#M32873</link>
    <description>&lt;P&gt;Did you ever come up with a solution? We're going through this process now and running into pretty much the same issue. Our existing Enterprise users are all in the format &lt;A href="mailto:doej@domain" target="_blank"&gt;doej@domain&lt;/A&gt;&amp;nbsp;(or domain\\doej), but Azure sends the username as &lt;A href="mailto:john.doe@domain.com" target="_blank"&gt;john.doe@domain.com&lt;/A&gt;&amp;nbsp;If we allow users to create an account without invitation, they are able to login, but it creates a brand new username. If push comes to shove, we can just get rid of all the old users and add new ones, but it would be nice if we can avoid that.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2022 18:06:37 GMT</pubDate>
    <dc:creator>JCGuarneri</dc:creator>
    <dc:date>2022-04-01T18:06:37Z</dc:date>
    <item>
      <title>Converting authentication from unique ArcGIS online users to Enterprise Azure AD users</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1061972#M30311</link>
      <description>&lt;P&gt;Currently we're using ArcGIS online and using our domain email addresses with unique passwords to login. We're attempting to convert to Azure AD authentication. I'd like to match the Enterprise usernames to the usernames we're currently using, however I'm not sure what/where I need to do this.&lt;BR /&gt;&lt;BR /&gt;I've gotten the SAML link to work in the Azure AD Enterprise Apps, however when logging into ArcGIS enterprise with my AD creds, I get an error:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Unable to sign in, logins are by invitation only. Please contact the administrator of this web site to access this site. IdpUsername: 'user@mydomain.com' Username: 'user@mydomain.com_MyCompanyShortname'"&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;user@mydomain.com&lt;/STRONG&gt; is an existing user account in ArcGIS online. I assume I need to update the User attributes &amp;amp; claims in my Azure AD Enterprise App to pass along this info? I'm not sure what I need to do and the help documentation isn't entirely clear.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Help documentation in question:&amp;nbsp;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/configuring-a-saml-compliant-identity-provider-with-your-portal.htm#ESRI_SECTION1_1E9996AB78AD47F7BE14B7DD5598BE2F" target="_blank"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/configuring-a-saml-compliant-identity-provider-with-your-portal.htm#ESRI_SECTION1_1E9996AB78AD47F7BE14B7DD5598BE2F&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 19:00:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1061972#M30311</guid>
      <dc:creator>ChipSmith09</dc:creator>
      <dc:date>2021-05-26T19:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Converting authentication from unique ArcGIS online users to Enterprise Azure AD users</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1160376#M32873</link>
      <description>&lt;P&gt;Did you ever come up with a solution? We're going through this process now and running into pretty much the same issue. Our existing Enterprise users are all in the format &lt;A href="mailto:doej@domain" target="_blank"&gt;doej@domain&lt;/A&gt;&amp;nbsp;(or domain\\doej), but Azure sends the username as &lt;A href="mailto:john.doe@domain.com" target="_blank"&gt;john.doe@domain.com&lt;/A&gt;&amp;nbsp;If we allow users to create an account without invitation, they are able to login, but it creates a brand new username. If push comes to shove, we can just get rid of all the old users and add new ones, but it would be nice if we can avoid that.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 18:06:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1160376#M32873</guid>
      <dc:creator>JCGuarneri</dc:creator>
      <dc:date>2022-04-01T18:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Converting authentication from unique ArcGIS online users to Enterprise Azure AD users</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233383#M34625</link>
      <description>&lt;P&gt;I am currently going through the exact same issue as the original post, and I agree there is virtually no supporting documentation for how to resolve this issue.&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/487786"&gt;@ChipSmith09&lt;/a&gt;&amp;nbsp;were you able to get this working? I'd love to know how to get it resolved.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 19:55:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233383#M34625</guid>
      <dc:creator>KevinCutsforth</dc:creator>
      <dc:date>2022-11-18T19:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Converting authentication from unique ArcGIS online users to Enterprise Azure AD users</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233418#M34626</link>
      <description>&lt;P&gt;You can't link them.&amp;nbsp; You need to recreate each user, as a SAML2 user, transfer any permissions/content and then deprecate the old user.&amp;nbsp; I believe there are example scripts online and also potentially third party admin tools that can help with the migration.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 21:35:02 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233418#M34626</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-11-18T21:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Converting authentication from unique ArcGIS online users to Enterprise Azure AD users</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233713#M34627</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/413165"&gt;@Scott_Tansley&lt;/a&gt;&amp;nbsp;. We ended up doing it in batches, so I wrote a script that took the old username, email address, first name, and last name as a csv input. It created each new user with the email address, then transferred items, groups, permissions, etc. to the new user, and finally deleted the old user. It wasn't too hard to set up, and a good opportunity to get to know the admin module of the Python API.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 13:15:27 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/converting-authentication-from-unique-arcgis/m-p/1233713#M34627</guid>
      <dc:creator>JCGuarneri</dc:creator>
      <dc:date>2022-11-21T13:15:27Z</dc:date>
    </item>
  </channel>
</rss>

