<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatically Assign Users to Groups in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221290#M12777</link>
    <description>&lt;P&gt;Yeah so the MMC component is to do with old-skool (still important) management of an AD.&amp;nbsp; AD's and traditional Integrated Windows Authentication work great in internal environments with old-fashioned network protocols.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAML2 works as a technology layer on top of that which basically 'webifies' it so that you can authenticate to web apps and resources (like ArcGIS Enterprise) that 'may not' be hosted on your internal environment.&amp;nbsp; This is great for current/future architectures and the right choice.&lt;/P&gt;&lt;P&gt;Your IT department is going to need to guide you here on what you use.&amp;nbsp; That internal AD list of users/groups can be shared directly using Active Directory Federation Services, but that's a bit old hat itself now.&amp;nbsp; Changes to the AD can also be broadcast to Azure AD or to the likes of OKTA (and others).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each has different capabilities and configurations and some of that depends on licensing.&lt;/P&gt;&lt;P&gt;So if, for example, your organisation uses Azure AD, then your Azure Ad admin needs to confirm that they are broadcasting those groups as a part of the SAML2 token.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 20:49:40 GMT</pubDate>
    <dc:creator>Scott_Tansley</dc:creator>
    <dc:date>2022-10-12T20:49:40Z</dc:date>
    <item>
      <title>Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221111#M12769</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I need some help understanding my Enterprise Portal identity store. I have manually set up groups in Enterprise Portal (10.8.1) that roughly correspond to the Active Directory user groups within the organization (Parks, Police, Fire, Assessing, Engineering etc). The Portal is configured for single sign-on where users are simply presented with the blue ESRI sign in button and their AD credentials are passed to the Portal. Additionally, the Portal is configured to automatically create user account if they have not yet signed in. This is the thing I want to work on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;My goal is to automatically place new users into Portal groups based on AD groups they are a part of, but this is where I get a little confused (I wasn’t primarily responsible for setting this up when we initially rolled out our Portal). So clearly there is some relationship between our Portal sign in configuration and our Windows AD. In the organization’s security settings, the login redirect hits our AD server, I can download the metadata xml, all that. But when I looking at the Identity Store config in the PortalAdmin directory, it shows that the Portal is configured with the type BUILTIN. I must not understand completely because it doesn’t &lt;EM&gt;seem&lt;/EM&gt; to make sense that user store configuration would be built in if there is such a relationship with the actual AD.&lt;/P&gt;&lt;P&gt;How do I appropriately configure the Portal to allow for automatic group placement when a new member signs in for the first time (without removing any currently existing Portal users in the process, if at all possible)? I’m not sure if I’ve provided enough/the right info for anyone to help out, so let me know if there’s anything else I can provide.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:30:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221111#M12769</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-12T14:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221114#M12770</link>
      <description>&lt;P&gt;From what you described, it appears that your Enterprise deployment is configured with SAML and not the traditional Active Directory connection. To have users added to groups, you would need to edit the SAML configuration (Settings -&amp;gt; Security -&amp;gt; Logins) and verify&amp;nbsp;&lt;EM&gt;Enable SAML base group membership&lt;/EM&gt; is turned on. The link below details how to configure this in more detail&lt;/P&gt;&lt;P&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979" target="_blank"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:40:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221114#M12770</guid>
      <dc:creator>ReeseFacendini</dc:creator>
      <dc:date>2022-10-12T14:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221116#M12771</link>
      <description>&lt;P&gt;Ah yes, so I did do that, and then created a new group, set the property in the settings so that only members of "SEC-GroupName" can join. Then we created a test user belonging to that group in Active Directory (to have a fresh faced login) and then I used that account to sign in to the Portal for the first time and they were not placed into the Portal group.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:43:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221116#M12771</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-12T14:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221286#M12775</link>
      <description>&lt;P&gt;Do you know what your SAML2 Identity Provider is?&amp;nbsp; You have to configure it to broadcast the groups that your users belong to as a part of the SAML2 token exchange.&lt;/P&gt;&lt;P&gt;What is happening behind the scenes is that the IDP will send a token for 'user1' , and if that same token has the SEC-GroupName in it, then when they log in there is a 'text match' which gives them the privileges.&lt;/P&gt;&lt;P&gt;If user1 is logged in to the portal, and is later added to the group in the AD, then Portal is unaware of this until the user logs out and logs in (to the Portal).&amp;nbsp; This is because there isn't a direct connection to the AD.&amp;nbsp; The connection only happens at the point of the handshake between Portal and the IDP.&amp;nbsp; Therefore changes to the AD after that event do not get reflected in portal until the next handshake.&lt;/P&gt;&lt;P&gt;But I have seen some client sites where Azure AD (for example) has not been posting the group membership in the token, so Portal has nothing to match against.&amp;nbsp; You may need to check the IDP end of the equation as well.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 20:37:07 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221286#M12775</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-10-12T20:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221287#M12776</link>
      <description>&lt;P&gt;I'm not 100% sure what the SAML2 provider is. Or rather, I know that we use Microsoft Active Directory (Microsoft Management Console?), but is that the same thing as the Provider? That would make the most sense to me anyway.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 20:39:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221287#M12776</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-12T20:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221290#M12777</link>
      <description>&lt;P&gt;Yeah so the MMC component is to do with old-skool (still important) management of an AD.&amp;nbsp; AD's and traditional Integrated Windows Authentication work great in internal environments with old-fashioned network protocols.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAML2 works as a technology layer on top of that which basically 'webifies' it so that you can authenticate to web apps and resources (like ArcGIS Enterprise) that 'may not' be hosted on your internal environment.&amp;nbsp; This is great for current/future architectures and the right choice.&lt;/P&gt;&lt;P&gt;Your IT department is going to need to guide you here on what you use.&amp;nbsp; That internal AD list of users/groups can be shared directly using Active Directory Federation Services, but that's a bit old hat itself now.&amp;nbsp; Changes to the AD can also be broadcast to Azure AD or to the likes of OKTA (and others).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each has different capabilities and configurations and some of that depends on licensing.&lt;/P&gt;&lt;P&gt;So if, for example, your organisation uses Azure AD, then your Azure Ad admin needs to confirm that they are broadcasting those groups as a part of the SAML2 token.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 20:49:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221290#M12777</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-10-12T20:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221496#M12782</link>
      <description>&lt;P&gt;Alright, that's good info. We do have ADFS, so if I read correctly, I would have the ability to share those group names with ADFS but SAML2 is the preferred method? Do you have any resources or walkthroughs that you know of that I could point the other IT folks to for reference?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 13:03:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1221496#M12782</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-13T13:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226667#M12840</link>
      <description>&lt;P&gt;So my network admin thinks that we should be able to implement this feature, but is looking for some examples of other organizations that have made it work. Are there any viewers of this thread that have successfully implemented automatic group assignation and would be willing to share their experiences?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 16:25:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226667#M12840</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-28T16:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226873#M12841</link>
      <description>&lt;P&gt;Apologies, I didn't see this response.&amp;nbsp; The instructions for configuring ADFS are here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/configure-adfs.htm" target="_blank" rel="noopener"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/configure-adfs.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Make sure you enable the SAML based group membership in the portal - you can edit it after the fact as well:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Enable SAML based group membership&lt;/SPAN&gt;—Enable this option to allow organization members to link specified&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SAML-based groups to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ArcGIS Enterprise&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;groups during the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://enterprise.arcgis.com/en/portal/11.0/administer/windows/create-groups.htm" target="_blank" rel="noopener"&gt;group creation process&lt;/A&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;You will be able to export the SP metadatafile, which you pass to you network administrator who need to pay particular attention to:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;With this claim,&amp;nbsp;AD FS&amp;nbsp;sends attributes with the names&amp;nbsp;&lt;SPAN class=""&gt;givenname&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;surname&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;email&lt;/SPAN&gt;, and&amp;nbsp;&lt;SPAN class=""&gt;group membership&lt;/SPAN&gt;&amp;nbsp;to&amp;nbsp;ArcGIS Enterprise&amp;nbsp;after authenticating the user.&amp;nbsp;ArcGIS Enterprise&amp;nbsp;then uses the values received in the&amp;nbsp;&lt;SPAN class=""&gt;givenname&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;surname&lt;/SPAN&gt;, and&amp;nbsp;&lt;SPAN class=""&gt;email&lt;/SPAN&gt;&amp;nbsp;attributes and populates the first name, last name, and email address of the user account. The values in the group attribute are used to update the user's group membership.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;H5&gt;&lt;EM&gt;Note:&lt;/EM&gt;&lt;/H5&gt;&lt;P&gt;&lt;EM&gt;If you selected the&amp;nbsp;&lt;SPAN class=""&gt;Enable SAML based group membership&lt;/SPAN&gt;&amp;nbsp;option when registering&amp;nbsp;&lt;SPAN class=""&gt;AD FS&lt;/SPAN&gt;&amp;nbsp;as the&amp;nbsp;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&amp;nbsp;IDP, membership for each user is obtained from the&amp;nbsp;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&amp;nbsp;assertion response received from the identity provider every time the user successfully signs in. For information on linking&amp;nbsp;&lt;SPAN class=""&gt;SAML&lt;/SPAN&gt;&amp;nbsp;groups, see&amp;nbsp;&lt;A href="https://enterprise.arcgis.com/en/portal/11.0/administer/windows/create-groups.htm" target="_blank" rel="noopener"&gt;Create groups&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;After it's configured, and it's easy on both end, you start creating groups in portal and if the syntax of the group name is an exact match of the name presented by ADFS then you'll get the auto assignment your looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 29 Oct 2022 23:23:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226873#M12841</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-10-29T23:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226874#M12842</link>
      <description>&lt;P&gt;I look after about 30 clients, mostly Local Government and Utilities.&amp;nbsp; Your network admin can reach out to me via direct message on my profile or LinkedIn.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This whole subject is pretty BAU now.&amp;nbsp; I would say it's tried and trusted if that's the issue?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 23:25:48 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1226874#M12842</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-10-29T23:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227011#M12843</link>
      <description>&lt;P&gt;Thanks again for following up. I already have a bunch of groups - I'm kind of doing this retroactively. Does the selected ADFS group name applied to the group need to happen before any members are present in the group, or should it just apply to any new sign-ins? The reason I ask is because I'm fairly certain I've done these steps but my test of a new user didn't assign them to a group as I expected.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 12:47:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227011#M12843</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-10-31T12:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227265#M12844</link>
      <description>&lt;P&gt;Has your network admin set ADFS to forward groups?&amp;nbsp; The last message said they were hopeful they could do this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 21:24:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227265#M12844</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-10-31T21:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227853#M12851</link>
      <description>&lt;P&gt;I believe he has. I sent you a DM that contains a snapshot of the relay and to my untrained eye it appears that group forwarding should be working.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 12:35:16 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1227853#M12851</guid>
      <dc:creator>ZachBodenner</dc:creator>
      <dc:date>2022-11-02T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Automatically Assign Users to Groups</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1408071#M14970</link>
      <description>&lt;P&gt;Hi! I have a bit of a follow up question on this thread. Our org has set up a SSO SAML login that passes a memberOf attribute through each login request. Using SAML Tracer, we see that the memberOf information comes through like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;CN=[value1],OU=[value2],dc=[value3],dc=[value4],dc=[value5]&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;lt;/&lt;SPAN class=""&gt;saml:AttributeValue&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;When we are in our Portal setting up groups, how exactly do we need to specify the Group Name setting under "Being a member of a SAML group"? Is it just the [value1] item in the example above? Do we need to somehow concatenate all the values together? Do we need quotes? Any help will be appreciated!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 17:40:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/automatically-assign-users-to-groups/m-p/1408071#M14970</guid>
      <dc:creator>GrantSmith122</dc:creator>
      <dc:date>2024-04-10T17:40:03Z</dc:date>
    </item>
  </channel>
</rss>

