<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arcgis Enterprise security in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412521#M5718</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Shafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially it all depends on how you share the application from within Portal for ArcGIS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance if you only wanted members of Portal for ArcGIS to access the web application then the application would need to be shared with organization. Then all named users of Portal for ArcGIS would have access to the application.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted members of a particular group to access the web application then the application would need to be shared with that group. Then all named users of Portal for ArcGIS whom are members of the group would have access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you created an application and wanted to grant public access but not require them to be a named user within Portal for ArcGIS. Then you'd want to enable Anonymous access and then share the web application with Everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this information helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Jun 2015 22:12:10 GMT</pubDate>
    <dc:creator>DustinHobbs</dc:creator>
    <dc:date>2015-06-23T22:12:10Z</dc:date>
    <item>
      <title>Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412520#M5717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm using Develop edition of WAB where I build custom widgets and download the application and deploy it locally. So at end I will be having multiple web application and also I have some other Non-GIS application. I wrap the downloaded WAB application in aspx (.net) page for security reasons. I know I can have only one application based on WAB and can show /hide widgets and load different web maps loading different configuration settings but I assume that will not make any difference related to security and also I will be having some other applications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although I have ADFS in place and we want SSO in our all applications and I saw it can achieved using ArcGIS Portal ( I will use portal only for creating web maps and assign permissions). But I assume we need &lt;STRONG&gt;named users&lt;/STRONG&gt; for portal for giving permission to web maps that we will usedn developer edition of WAB applications but that can be a rider for me, Am I right? ( I want to make sure because I will talk to management and put this case)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other options where can achieve same may be using GIS server authentication and ArcGIS services server through proxy.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.esri.com/migrated-users/3101"&gt;Robert Scheitlin, GISP&lt;/A&gt;​&lt;/P&gt;&lt;P&gt;Since I'm assume you are using WAB and secure services can you please enlighten me with your valuable inputs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2015 19:49:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412520#M5717</guid>
      <dc:creator>shafitrumboo</dc:creator>
      <dc:date>2015-06-23T19:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412521#M5718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings Shafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially it all depends on how you share the application from within Portal for ArcGIS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance if you only wanted members of Portal for ArcGIS to access the web application then the application would need to be shared with organization. Then all named users of Portal for ArcGIS would have access to the application.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted members of a particular group to access the web application then the application would need to be shared with that group. Then all named users of Portal for ArcGIS whom are members of the group would have access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you created an application and wanted to grant public access but not require them to be a named user within Portal for ArcGIS. Then you'd want to enable Anonymous access and then share the web application with Everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this information helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2015 22:12:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412521#M5718</guid>
      <dc:creator>DustinHobbs</dc:creator>
      <dc:date>2015-06-23T22:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412522#M5719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not my question I don't have serve applications from Portal contrary to that I download the app, deploy and serve it on my web server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to avoid if possible to named users because of its license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 07:02:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412522#M5719</guid>
      <dc:creator>shafitrumboo</dc:creator>
      <dc:date>2015-06-24T07:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412523#M5720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could please clarify your question? I understand that you are using the WAB Developer addition and have it deployed to your web server. I guess I'm confused on your concern with named users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this type of configuration named users would not come into play unless the ArcGIS Server, where the map services are being consuming from, is federated with Portal for ArcGIS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 15:04:16 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412523#M5720</guid>
      <dc:creator>DustinHobbs</dc:creator>
      <dc:date>2015-06-24T15:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412524#M5721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me explain you my workflow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I publish the service using arcgis server&lt;/P&gt;&lt;P&gt;2. I create a web map using Arcgis portal&lt;/P&gt;&lt;P&gt;3. Using developer edition of WAB We created multiple web application in sync with our business requirements.&lt;/P&gt;&lt;P&gt;4. We download these web application and deploy them on our web server&lt;/P&gt;&lt;P&gt;5. We also wrap them in .net for security reasons and also we integrate them with ADFS&lt;/P&gt;&lt;P&gt;6. We have other application that are not arcgis based&lt;/P&gt;&lt;P&gt;7. We use ADFS3 to have SSO for all applications.&lt;/P&gt;&lt;P&gt;8. We have one application for managing applications access. In our database we have list of application and list of assigned application to user.&lt;/P&gt;&lt;P&gt;9. Also Our default home page we call it app launcher lists application depends on user permissions after successful login using ADFS. The permission code and configuration is custom build but apparently we use AD users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is working fine perfectly but you see we have not done any permissions for ArcGIS services or we maps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I&amp;nbsp; federated ArcGIS Server site with portal and configured ADFS. Then I shared the Arcgis service (&lt;STRONG&gt;EIA_Service&lt;/STRONG&gt;) and web map (&lt;STRONG&gt;EIA_WEBMAP)&lt;/STRONG&gt; with one group ( I have added&amp;nbsp; one AD user to that group also). If I login in&amp;nbsp; Arcgis portal using that user through ADFS I'm able access the items that are shared with that user. But when I access the application after successful login through ADFS (This application is also relying partner inADFS) where these &lt;STRONG&gt;EIA_Service and &lt;/STRONG&gt; &lt;STRONG&gt;EIA_WEBMAP&lt;/STRONG&gt; is used it prompts me with login window again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: My application and ArcGIS portal are hosted on different servers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="113305" alt="ADFS2.jpg" class="image-1 jive-image" src="https://community.esri.com/legacyfs/online/113305_ADFS2.jpg" style="width: 620px; height: 384px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.esri.com/migrated-users/3176"&gt;Derek Law&lt;/A&gt;​ Please provide your thoughts&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.esri.com/migrated-users/62883"&gt;Jayanta Poddar&lt;/A&gt;​&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 19:01:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412524#M5721</guid>
      <dc:creator>shafitrumboo</dc:creator>
      <dc:date>2015-06-24T19:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412525#M5722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shafi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to give you something else to think about:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you login through ADFS into your WAB application you're only granted permission into that app. The SAML token passed I believe is valid only for that web app (service provider). The moment your web application tries to access a secured Portal WebMap (that's another SP) the login has to happen again (portal has no idea you have already logged in).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given your workflow, it looks to me for Portal ADFS configuration you need to configure Identity Provider initiated logins. Look here: &lt;A href="https://doc.arcgis.com/en/arcgis-online/reference/configure-adfs.htm" title="https://doc.arcgis.com/en/arcgis-online/reference/configure-adfs.htm"&gt;Configure Active Directory Federation Services—ArcGIS Online Help | ArcGIS&lt;/A&gt;&amp;nbsp; and here &lt;A href="http://stackoverflow.com/questions/12779532/diffrence-between-sp-initiated-sso-and-idp-initiated-sso" title="http://stackoverflow.com/questions/12779532/diffrence-between-sp-initiated-sso-and-idp-initiated-sso"&gt;http://stackoverflow.com/questions/12779532/diffrence-between-sp-initiated-sso-and-idp-initiated-sso&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way when user logs in once through the regular ADFS login page, it's ADFS that forwards the login request to the Service Provider (Portal). This should achieve the SSO you're looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2015 20:23:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412525#M5722</guid>
      <dc:creator>JonUjkani</dc:creator>
      <dc:date>2015-07-28T20:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412526#M5723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your email,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using ADFS 3 and can't change these things&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2016 12:10:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412526#M5723</guid>
      <dc:creator>shafitrumboo</dc:creator>
      <dc:date>2016-03-29T12:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412527#M5724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shafi trumboo,&lt;/P&gt;&lt;P&gt;I am having the same problem after having configured Portal for arcgis 10.3 with an authentification SAML2 as Service Provider and defined groups/users with Active Directory. &lt;/P&gt;&lt;P&gt;Calling secured web map services of the federated ArcGIS server from another server configured with SSO SAML2 as well, brings me the same login window.&lt;/P&gt;&lt;P&gt;Did configuring Portal for ArcGIS as an Identity Provider solve this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2016 19:31:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412527#M5724</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2016-07-26T19:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412528#M5725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having the same kind of problem as Shafi and there is still something I don't understand:&lt;/P&gt;&lt;P&gt;why is this pop up showing up instead of redirecting to the SP Portal is configured to deal with. Then, the SP would handle the rest.&lt;/P&gt;&lt;P&gt;What have I missed ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2016 13:34:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412528#M5725</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2016-08-09T13:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412529#M5726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested &lt;SPAN style="background-color: #ffffff;"&gt;configuring Identity Provider initiated logins and it did not solve the problem (maybe I missed something but I don't think so).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;I think it is rather that you have to use &lt;SPAN style="color: #000000; background-color: #fefefe;"&gt;OAuth 2.0 based authentication in the Javascript in order to get an 'SSO experience'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://developers.arcgis.com/javascript/3/jshelp/ags_secureservices.html#Oauth" style="line-height: 1.73;" title="https://developers.arcgis.com/javascript/3/jshelp/ags_secureservices.html#Oauth"&gt;Working with secure resources | Guide | ArcGIS API for JavaScript 3.17&lt;/A&gt;&lt;SPAN style="line-height: 1.73;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And this did the solve the pop-up problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.73;"&gt;Nicolas&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2016 08:49:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412529#M5726</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2016-08-23T08:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412530#M5727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What was your final solution?. Since we are using ADFS for IDP and we non-arcgis application also. They work perfectly with ADFS but I wonder why not ArcGIS Services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shafi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2016 07:57:23 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412530#M5727</guid>
      <dc:creator>shafitrumboo</dc:creator>
      <dc:date>2016-09-06T07:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Arcgis Enterprise security Single Sign-On (SSO)</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412531#M5728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did someone found any resolution for this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Apr 2019 11:01:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/arcgis-enterprise-security-single-sign-on-sso/m-p/412531#M5728</guid>
      <dc:creator>anirudhnegi1</dc:creator>
      <dc:date>2019-04-01T11:01:44Z</dc:date>
    </item>
  </channel>
</rss>

