We need a Access Management interface, based on SCIM v2 for separating the Identity en the Access management layers.
Portal has already support for the standards for Single Sign On: SAML. This is for Identity management (authentication).
Our security standards require to separate the Access management (authorization). THis is company wide implemented via the SCIM interface. All applications within our company are now required to have a SAML and a SCIM interface.
My request/idea is to implement this SCIM interface to Portal.
Basic workflow when working with SAML + SCIM:
1 - 4 are now in place.
5 -7 have to be implemented using new SCIM v2 interface.
SCIM v2 is an open standard, and worldwide.
Above examples include groups. It must also include roles/licenses (lvl1/lvl2 with the new names for Creator, Fieldworker etc..) and the special licenses (arcgis pro, navigator, etc..)
To manage user identities in cloud based applications and services easier we need an access management interface base on SCIM V2.
The idea is the same as already mentioned in the idea https://community.esri.com/t5/arcgis-enterprise-ideas/access-management-based-on-scim-v2-interface-f...
We need that for groups and roles.
We would also need this functionality.
Strongly support the integration of SCIM for user and group provisioning. This is a core feature and requirement of our other enterprise applications, so would be good to see this developed.
Strongly support the integration of SCIM for user and group provisioning. This is a core feature and requirement of our other enterprise applications, so would be good to see this developed.
I support this one too! Enterprise needs to support modern Enterprise IT tools for IAM.
Closing as a duplicate of https://community.esri.com/t5/arcgis-enterprise-ideas/access-management-based-on-scim-v2-interface-f.... Please vote on that idea!
In case anyone needs it, here is a user management script that can be extended to give you near SCIM capabilities. It's not perfect, but it was the solution I came up with to deal with the user issue.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.