<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure Active Directory integration with ArcGIS Online in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92795#M3519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;User types and roles exist outside of the user's identity store, so the new user defaults would apply upon the first sign-in of an enterprise account when automatically added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an option when configuring the enterprise logins to allow both authentication methods (SAML and ArcGIS) or allow only enterprise logins. Typically when a customer is wanting to implement enterprise logins in an established organization the recommendation is to allow some users to login with their new enterprise account, set the user type, role, and group membership for that new user to match their existing built-in account, then transfer all owned items from the built-in account to the new enterprise login account. If you find yourself short on additional user licenses, you can do this in batches until everyone is migrated to the new enterprise logins. Once all users are migrated to the enterprise logins, you could disable the built-in authentication option if you desired to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Aug 2020 13:56:54 GMT</pubDate>
    <dc:creator>ChristopherPawlyszyn</dc:creator>
    <dc:date>2020-08-18T13:56:54Z</dc:date>
    <item>
      <title>Azure Active Directory integration with ArcGIS Online</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92792#M3516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am trying to set the identity provider in ArcGIS Online to use Azure Active Directory to configure ArcGIS Online Single Sign-On.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found this tutorial that walks-through the process:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/arcgis-tutorial" title="https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/arcgis-tutorial"&gt;Tutorial: Azure Active Directory integration with ArcGIS Online | Microsoft Docs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while the documentation perfectly outlines the steps,&amp;nbsp;it is still unclear to me How ArcGIS Roles "Groups" and User levels works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Is ArcGIS users groups will be managed by the AD groups “the groups need to exist in the Active Directory” in order to use them and place users in that group.&amp;nbsp; Or we still can utilize the native and custom groups in ArcGIS online?&lt;/P&gt;&lt;P&gt;The reason I am asking, is&amp;nbsp;because&amp;nbsp; I have a lot&amp;nbsp;of&amp;nbsp;&amp;nbsp;custom groups&amp;nbsp; that I keep in ArcGIS Online environment but I don't want them to be created in AD :&lt;/P&gt;&lt;P&gt;Admin, Editor, Viewer, Editor Limited, Site A Data&amp;nbsp;Download Only, Site A Data Viewer Only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2020 20:43:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92792#M3516</guid>
      <dc:creator>AhmadSALEH1</dc:creator>
      <dc:date>2020-08-17T20:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Active Directory integration with ArcGIS Online</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92793#M3517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://community.esri.com/migrated-users/95822"&gt;Ahmad SALEH&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configuring a SAML identity store in your ArcGIS Online organization, you have the option to control group membership based on the groups that are listed in users' SAML assertions when authenticating with the identity provider, but that does not mean that you cannot use built-in groups as well. The plus side of managing the group membership in Azure AD is you only have to update one location to modify access to both AD-based resources as well as ArcGIS Online resources within that group. If you choose to implement enterprise groups using your identity provider, you'll need to make sure the group assertion claim is reaching ArcGIS Online from the identity provider since that is how users join the groups automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979" title="https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979"&gt;Create groups—Portal for ArcGIS | Documentation for ArcGIS Enterprise&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any additional questions!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Aug 2020 22:07:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92793#M3517</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2020-08-17T22:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Active Directory integration with ArcGIS Online</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92794#M3518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome, Thanks Chris.&lt;/P&gt;&lt;P&gt;so to summarize, for the user groups, I can&amp;nbsp; &amp;nbsp;use&amp;nbsp;either AD groups or ArcGIS Online built in groups.&lt;/P&gt;&lt;P&gt;Does that apply to users Roles and user types too?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.esri.com/legacyfs/online/503777_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, one more question, what happens to the current/existing users&amp;nbsp; I assume that they will still be able to use the ArcGIS Online Login, right ? is there a way to switch them all to SAML login or this needs to be done manually for every user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Ahmad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:32:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92794#M3518</guid>
      <dc:creator>AhmadSALEH1</dc:creator>
      <dc:date>2020-08-18T13:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Active Directory integration with ArcGIS Online</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92795#M3519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;User types and roles exist outside of the user's identity store, so the new user defaults would apply upon the first sign-in of an enterprise account when automatically added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an option when configuring the enterprise logins to allow both authentication methods (SAML and ArcGIS) or allow only enterprise logins. Typically when a customer is wanting to implement enterprise logins in an established organization the recommendation is to allow some users to login with their new enterprise account, set the user type, role, and group membership for that new user to match their existing built-in account, then transfer all owned items from the built-in account to the new enterprise login account. If you find yourself short on additional user licenses, you can do this in batches until everyone is migrated to the new enterprise logins. Once all users are migrated to the enterprise logins, you could disable the built-in authentication option if you desired to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2020 13:56:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/92795#M3519</guid>
      <dc:creator>ChristopherPawlyszyn</dc:creator>
      <dc:date>2020-08-18T13:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Active Directory integration with ArcGIS Online</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/1146910#M32494</link>
      <description>&lt;P&gt;interesting question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured it as well and it is not working:&amp;nbsp;&lt;SPAN&gt;AADSTS500113&amp;nbsp;&amp;nbsp;No reply address is registered for the application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I used the enterprise application tempate ArcGIS Online...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 12:21:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/azure-active-directory-integration-with-arcgis/m-p/1146910#M32494</guid>
      <dc:creator>Mannus_Etten</dc:creator>
      <dc:date>2022-02-23T12:21:44Z</dc:date>
    </item>
  </channel>
</rss>

