<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML Authentication for Third Party in ArcGIS Online Questions</title>
    <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706888#M68829</link>
    <description>&lt;P&gt;Yeah, I wouldn't necessarily expect there to be any Esri documentation about it because this is something that is done at the Azure level vs. the Esri level. Just like how Esri doesn't really tell you how to create accounts in Azure. They just tell you how to link Azure to AGOL so you can sign into AGOL with your Azure login.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2026 15:18:00 GMT</pubDate>
    <dc:creator>RyanUthoff</dc:creator>
    <dc:date>2026-06-08T15:18:00Z</dc:date>
    <item>
      <title>SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706844#M68821</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are looking to migrate our built-in accounts to SAML set up in Azure AD. There is no issue for internal users who have an AD account.&lt;/P&gt;&lt;P&gt;We also have about 300 external contractors, who currently have access but they do not have their own AGOL license. Some of the users only need temporary access for 3-6 months for a specific project.&lt;/P&gt;&lt;P&gt;Do they need to have full account set up in our Azure AD ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or does B2B work i.e. are they added as guests in our Azure AD and by doing SAML claims transform in Azure, they can be authenticated using their own IDP?&lt;/P&gt;&lt;P&gt;Can someone please point me to ESRI architecture documentation how the external users can be set up for authentication using SAML.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any recommended option(s) ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 13:28:16 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706844#M68821</guid>
      <dc:creator>khem1000</dc:creator>
      <dc:date>2026-06-08T13:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706849#M68822</link>
      <description>&lt;P&gt;No, they don't necessarily need full access in your Azure AD tenant. All you need to do is invite them as an external user in Azure AD, which essentially adds them as a guest account in your tenant.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you invite them as an external user, you do NOT manage their account (so no password resets, no email management, etc.). The contractor's organization is still responsible for that. The only thing you can really control is what they have access to within your Azure tenant (such as giving them permissions to AGOL).&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the AGOL side of things, you would manage it the exact same was as your internal users.&lt;/P&gt;&lt;P&gt;And a final note, you can invite non-Microsoft accounts as well. They work just about the same as Microsoft accounts.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 13:45:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706849#M68822</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2026-06-08T13:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706875#M68826</link>
      <description>&lt;P&gt;Thanks. This sounds quite promising.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand the benefit of using guest accounts, but does the SAML assertion provided for the guest users work reliably without needing further customisation in Azure?&lt;/P&gt;&lt;P&gt;Has anyone got this working?&lt;/P&gt;&lt;P&gt;I assume to revoke access, the user simply need to be removed from Azure and their membership and content deleted in AGOL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 14:34:25 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706875#M68826</guid>
      <dc:creator>khem1000</dc:creator>
      <dc:date>2026-06-08T14:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706877#M68827</link>
      <description>&lt;P&gt;For the purposes of AGOL, it works exactly the same as an Azure AD account that your organization owns. You invite them to your Azure AD tenant, and then the end user needs to accept the invitation from Microsoft. After that, you just set the permissions just as if it were an account that your organization owns.&lt;/P&gt;&lt;P&gt;Yes, I got this working. This is a common workflow.&lt;/P&gt;&lt;P&gt;Again, you would treat revoking access the same as if it were an account that your organization owns. You delete the account and/or content from AGOL, then delete the account from Azure (or at least remove them from the AGOL enterprise app that gives them access to AGOL).&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 14:51:01 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706877#M68827</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2026-06-08T14:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706887#M68828</link>
      <description>&lt;P&gt;Thanks for confirming.&lt;/P&gt;&lt;P&gt;This appears straightforward, but I couldn't find any ESRI documentation on using guest accounts.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 15:09:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706887#M68828</guid>
      <dc:creator>khem1000</dc:creator>
      <dc:date>2026-06-08T15:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Authentication for Third Party</title>
      <link>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706888#M68829</link>
      <description>&lt;P&gt;Yeah, I wouldn't necessarily expect there to be any Esri documentation about it because this is something that is done at the Azure level vs. the Esri level. Just like how Esri doesn't really tell you how to create accounts in Azure. They just tell you how to link Azure to AGOL so you can sign into AGOL with your Azure login.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 15:18:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-online-questions/saml-authentication-for-third-party/m-p/1706888#M68829</guid>
      <dc:creator>RyanUthoff</dc:creator>
      <dc:date>2026-06-08T15:18:00Z</dc:date>
    </item>
  </channel>
</rss>

