OpenID Connect group membership

747
4
11-21-2022 02:29 PM
Status: Open
AngusHooper1
Occasional Contributor III

SAML identity providers integrated with ArcGIS Enterprise can support group membership. Similarly, it would be great to support OIDC backed group membership through calls to a groups or memberOf (etc) property.

Tags (3)
4 Comments
sodtom
by

Even this is NOT a part nor compliance with current OIDC standard scopes / claims, this is feature that has been asked from several ArcGIS clients. Adding support for custom or enhanced scopes / claims like groups would be very helpful.

NicolasGIS

+1 !

As it is does not seem to be standard to OIDC protocol (correct me if I am wrong, not an expert !), a configurable claim (aka not hardcoded) would be very useful to retrieve groups membership experience of SAML !

Thanks for listening 

jmp601
by

Voicing my support for this feature too! This would be tremendously helpful as we do this with a lot of other vendors already. It allows our cloud SA's to manage groups in our Azure tenant which will map them all to the appropriate group in the ESRI world. 

Martin1

We would be interested in OpenID Connect, but will stay with SAML as long as group memberships are not available.