<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding enterprise login for AGOL in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679929#M33806</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your feedback Danny. We did get it done, it works great. AGO/ADFS via &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in AD&lt;/P&gt;&lt;P&gt;-claims aware trust&lt;/P&gt;&lt;P&gt;-access control , permit specific group&lt;/P&gt;&lt;P&gt;-add relying party trust&lt;/P&gt;&lt;P&gt;-send LDAP attributes as claims&lt;/P&gt;&lt;P&gt;-dpwm;pad adfs federation metadata.xml&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in AGO&lt;/P&gt;&lt;P&gt;-set enterprise login&lt;/P&gt;&lt;P&gt;-set identity provider via a&amp;nbsp; metadata.xml file from-encrypt assertion, update profiles on sign in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then start inviting AGO members.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 May 2019 16:06:59 GMT</pubDate>
    <dc:creator>CathleenAlmberg</dc:creator>
    <dc:date>2019-05-16T16:06:59Z</dc:date>
    <item>
      <title>Adding enterprise login for AGOL</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679927#M33804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we too are changing our AGO member seats to active directory authentication. My question is, can ADFS/SAML be activated on JUST ONE active directory group? Does anyone out there in GIS world have a setup like this? I'm trying to gauge if this is common practice or if we are heading into uncharted waters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your feedback is appreciated, thanks,&lt;/P&gt;&lt;P&gt;Cathy Almberg&lt;/P&gt;&lt;P&gt;GIS Specialist, City of Palm Coast FLorida&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:calmberg@palmcoastgov.com"&gt;calmberg@palmcoastgov.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;386.986.3741&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 17:27:07 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679927#M33804</guid>
      <dc:creator>CathleenAlmberg</dc:creator>
      <dc:date>2019-01-08T17:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding enterprise login for AGOL</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679928#M33805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cathy,&lt;/P&gt;&lt;P&gt;If I understand what you are asking, you want to know if you can limit the users who can sign in using SAML to your ArcGIS Online organization based on their membership in a particular AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say the easiest way to accomplish this would be on the ADFS side of things using an Access Control Policy.&amp;nbsp; See the following Microsoft doc on this:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-permit-or-deny-users-based-on-an-incoming-claim" title="https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-permit-or-deny-users-based-on-an-incoming-claim"&gt;Create a Rule to Permit or Deny Users Based on an Incoming Claim | Microsoft Docs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 18:20:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679928#M33805</guid>
      <dc:creator>DanielUrbach</dc:creator>
      <dc:date>2019-01-08T18:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Adding enterprise login for AGOL</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679929#M33806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your feedback Danny. We did get it done, it works great. AGO/ADFS via &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in AD&lt;/P&gt;&lt;P&gt;-claims aware trust&lt;/P&gt;&lt;P&gt;-access control , permit specific group&lt;/P&gt;&lt;P&gt;-add relying party trust&lt;/P&gt;&lt;P&gt;-send LDAP attributes as claims&lt;/P&gt;&lt;P&gt;-dpwm;pad adfs federation metadata.xml&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in AGO&lt;/P&gt;&lt;P&gt;-set enterprise login&lt;/P&gt;&lt;P&gt;-set identity provider via a&amp;nbsp; metadata.xml file from-encrypt assertion, update profiles on sign in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then start inviting AGO members.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2019 16:06:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/adding-enterprise-login-for-agol/m-p/679929#M33806</guid>
      <dc:creator>CathleenAlmberg</dc:creator>
      <dc:date>2019-05-16T16:06:59Z</dc:date>
    </item>
  </channel>
</rss>

