<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML-based enterprise groups in Portal not working? in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656494#M8979</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They (tech support) seemed to think that is the problem?! I certainly hope it is. The groups are based on SAML role membership. And yes we technically could bypass the defect but I work for a very large organization and it would impact much more than just me, so my IT department will not make the change.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Sep 2018 16:02:28 GMT</pubDate>
    <dc:creator>ShelbyZelonisRoberson</dc:creator>
    <dc:date>2018-09-25T16:02:28Z</dc:date>
    <item>
      <title>SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656490#M8975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've had a ticket with Esri for the past few months trying to figure this out, but wanted to throw it out to the community to see if anyone else is having the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Portal 10.6.1 and am trying to create Portal groups that are tied to enterprise SAML-based groups. I've followed all instructions here&amp;nbsp;&lt;A class="link-titled" href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979" title="https://enterprise.arcgis.com/en/portal/latest/administer/windows/create-groups.htm#ESRI_SECTION1_5E3FFFAA1B7E443FBB1E483E070B1979"&gt;Create groups—Portal for ArcGIS (10.6) | ArcGIS Enterprise&lt;/A&gt;&amp;nbsp;under the SAML-based IDP section, but still can't get it to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what happens:&amp;nbsp; I create a group in my Portal (e.g. "Test Group") and set it to only be able to be joined by Members of an Enterprise Group. I type the name exactly of my SAML-based enterprise group (e.g. "SAML_Test_Group") to link to "Test Group". My enterprise username is a member of "SAML_Test_Group", so in theory I should be able to log into the Portal, see the "Test Group", and be able to share content into it. Here's where the problem is. I can see the "Test Group", but I cannot share any content into it. I've tried adjusting every group setting possible, and also have had many other people try a similar workflow. On the SAML side of things, our IT group sees the SAML assertions when I access the group, so I think everything is working properly on that side of things. I think it's in the Portal where something is going wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been going back and forth with Esri tech support unsuccessfully for a few months. I was wondering if anyone else is having the same issue? Or is it working for you? I've searched GeoNet and can't find anything related.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2018 12:44:13 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656490#M8975</guid>
      <dc:creator>ShelbyZelonisRoberson</dc:creator>
      <dc:date>2018-09-06T12:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656491#M8976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say you can see the group, is that under "My Groups" or "My Organization's Groups"?&lt;/P&gt;&lt;P&gt;What attribute name are you using for the attribute chosen for group membership (e.g. &amp;lt;Attribute name="Group"&amp;gt; in the SAML response)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 05:11:24 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656491#M8976</guid>
      <dc:creator>DanielUrbach</dc:creator>
      <dc:date>2018-09-25T05:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656492#M8977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Danny - I meant to update this post. I recently came to a resolution with tech support. There is a bug on Esri's end that requests SAML:1.1 for the nameid instead of SAML:2.0. Hoping it gets fixed soon!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For anyone interested, it's BUG-000114084.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelby&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 12:21:25 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656492#M8977</guid>
      <dc:creator>ShelbyZelonisRoberson</dc:creator>
      <dc:date>2018-09-25T12:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656493#M8978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shelby,&lt;/P&gt;&lt;P&gt;I'm not entirely sure that bug would affect group membership to be honest.&lt;/P&gt;&lt;P&gt;Having said that, what identity provider are you using?&amp;nbsp; Most identity providers can be configured to send the nameid as SAML:2.0, effectively bypassing that defect.&lt;/P&gt;&lt;P&gt;-Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:57:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656493#M8978</guid>
      <dc:creator>DanielUrbach</dc:creator>
      <dc:date>2018-09-25T15:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656494#M8979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They (tech support) seemed to think that is the problem?! I certainly hope it is. The groups are based on SAML role membership. And yes we technically could bypass the defect but I work for a very large organization and it would impact much more than just me, so my IT department will not make the change.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 16:02:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656494#M8979</guid>
      <dc:creator>ShelbyZelonisRoberson</dc:creator>
      <dc:date>2018-09-25T16:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656495#M8980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shelby,&lt;/P&gt;&lt;P&gt;I understand that you cannot make the changes in the IdP.&lt;/P&gt;&lt;P&gt;The reason I don't believe that particular defect is blocking you from sharing content to a SAML-linked group is that the NameID is only used to generate the username for the SAML-based user in Portal.&amp;nbsp; The fact that you are able to sign in successfully makes me think that that defect is not affecting this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was your Portal upgraded to 10.6.1 or was it a fresh installation?&lt;/P&gt;&lt;P&gt;If you go to&amp;nbsp;&lt;A class="link-titled" href="https://jarvis.esri.com/portal/sharing/rest/community/users/dani7807" title="https://jarvis.esri.com/portal/sharing/rest/community/users/dani7807"&gt;https://&amp;lt;Portal FQDN&amp;gt;/&amp;lt;webadaptor&amp;gt;/sharing/rest/community/users/&lt;/A&gt;&amp;lt;SAML user&amp;gt;, is the group linked to a SAML group listed under User Groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 17:36:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656495#M8980</guid>
      <dc:creator>DanielUrbach</dc:creator>
      <dc:date>2018-09-25T17:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656496#M8981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Portal was upgraded to 10.6.1 but this was an issue at 10.6 also (10.6 was a fresh installation).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I go to the link you sent using my username, the SAML-linked Portal group is NOT listed under my User Groups.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, in the Portal, I can see the SAML-linked Portal group under "My Organization's Groups". The group is set to Private (only viewable by group members) so in theory if I wasn't in the group, wouldn't I not be able to see it? Side note: I did not create the group with my username so owning it is not the reason I can see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also took a look the group page at &lt;A href="https://&amp;lt;portalfqdn&amp;gt;/&amp;lt;webadaptor&amp;gt;/sharing/rest/community/groups/&amp;lt;samlgroupname&amp;gt;"&gt;https://&amp;lt;portalfqdn&amp;gt;/&amp;lt;webadaptor&amp;gt;/sharing/rest/community/groups/&amp;lt;samlgroupname&amp;gt;&lt;/A&gt;. It lists Provider as "enterprise" and has the correct SAML group listed as the provider group name. However, when I click on Group Users, only the owner is listed as a user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's easier we could continue this offline and I could show you screenshots, etc - up to you. I appreciate the help, I'd really love to get this resolved especially if it has nothing to do with the Bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelby&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2018 10:40:34 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656496#M8981</guid>
      <dc:creator>ShelbyZelonisRoberson</dc:creator>
      <dc:date>2018-09-26T10:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656497#M8982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has this issue been resolved yet? I am recently trying to integrate our Idp with ArcGis. I run into the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use&amp;nbsp;Identityserver4 with Saml plugin, I could login using identities hosted on&amp;nbsp;&lt;SPAN&gt;Identityserver4 no problem. I use attribute &amp;lt;MemberOf&amp;gt;, so the group show up as the logged in user's "My Organization's group". But I can't add content to the group&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Group was created with settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;Who can view this group? -- Only group member&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;Who can join this group? --&amp;nbsp;&lt;SPAN style="color: #595959;"&gt;Members of an Enterprise Group&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;Who can contribute content to the group? --&amp;nbsp;&lt;SPAN style="color: #595959;"&gt;Group members&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;If you figured out a solution, could you please share with me?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #4c4c4c;"&gt;Update: It actually works, the default role I was using didn't have&amp;nbsp;privilege to share. So&amp;nbsp;there's no problem.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2018 16:54:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656497#M8982</guid>
      <dc:creator>KeChen</dc:creator>
      <dc:date>2018-11-27T16:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: SAML-based enterprise groups in Portal not working?</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656498#M8983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found out that I can only share content to an enterprise group when I am myself a member of the group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's in my opinion a bug because it does not follow the group settings and it makes it very difficult for administrators to share content in a senseful workflow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2020 06:16:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/saml-based-enterprise-groups-in-portal-not-working/m-p/656498#M8983</guid>
      <dc:creator>MarkusSchenardi</dc:creator>
      <dc:date>2020-04-09T06:16:10Z</dc:date>
    </item>
  </channel>
</rss>

