|
IDEA
|
We have always utilized a hybrid ArcGIS deployment - with our own ArcGIS servers and portal for internal use using secured services and referencing the services we would like to make public on AGOL. Up until deploying ArcGIS Enterprise 11.1 we had always utilized portal-tier authentication which allowed us to store credentials on services shared on AGOL as a token. Storing the token allows public users to view selected secure services on our internal ArcGIS Enterprise deployment without having to enter any credentials. Access to these services are typically limited via AGOL to only be accessible through specific published applications or URLs. With the deployment of ArcGIS Enterprise 11.1 we elected to federate our ArcGIS servers and integrate user credentials with IWA and later SAML. This allows internal users to experience a single sign on (SSO) when on the internal domains. However, AGOL does not have the ability to store a users credential when utilizing web-tier authentication. AGOL can only store token based credentials when using portal-tier authentication. Therefore, we cannot allow limited public access on AGOL to a selection of our internal secure services. Please develop a means to access secure portal services via a specified stored username/password from AGOL that could be authenticated using web-tier authentication. This would be appreciated on the service level and the app level. https://support.esri.com/en-us/knowledge-base/faq-what-is-the-difference-between-webtier-vs-gistier-000011833 https://support.esri.com/en-us/knowledge-base/problem-the-option-to-store-credentials-is-not-availabl-000012369 https://support.esri.com/en-us/knowledge-base/problem-the-option-to-store-credentials-is-not-visible-000015387
... View more
05-26-2023
07:13 AM
|
5
|
4
|
2152
|
|
POST
|
@Todd_Metzler, You note that with SAML authentication should help resolve the issue we are experiencing. Can you please elaborate on that a little further? We went ahead a configured our SAML identification provider with ArcGIS Enterprise and AGOL. However, we still are not able to store a credential on AGOL to access secured services on our Enterprise deployment. I believe SAML also does not use token based authentication to allow this to occur unless I missed something in configuring the authentication.
... View more
05-25-2023
06:45 AM
|
0
|
0
|
4479
|
|
POST
|
@RyanUthoff, Thanks for the quick reply. I to have not been able to find anything in the ESRI documentation. It does state that when using portal-tier authentication that SSO will not function. However, why can not you use a domain\user to access portal items from AGOL and why do they disable the save credentials when using web-tier authentication. I also tried making services from a AGOL-Portal collaboration public but have the same results.
... View more
05-19-2023
10:40 AM
|
0
|
1
|
4591
|
|
POST
|
We recently upgraded our enterprise deployment to 11.1 and as part of that process, we federated our ArcGIS server site with the portal. This allows us to utilize integrated Windows authentication (IWA) on our enterprise systems. Everything is working great with single sign-on (SSO) working seamlessly on our network when our portal is configured for web-tier authentication. However, we can no longer access secure services from ArcGIS Online (AGOL). AGOL does not give the option to save the credentials when adding a new URL-based item from our secure portal. If we switch our Portal to portal-tier authentication the option to store credentials with a service item appears and we can access the secure data from AGOL without a logon; however, we lose our SSO functionality, and network users have to manually sign into secured services. Am I missing something? Is there a workaround to be able to use web-tier authentication while still storing credentials on AGOL items? We are using AGOL to make available some of our secure services publically available from our enterprise systems. It has worked great in stand-alone deployments and on Portal when configured with portal-tier authentication. I just cannot get it to work when using web-tier authentication.
... View more
05-19-2023
09:52 AM
|
0
|
7
|
4628
|
|
POST
|
Thanks, @John_Tyll and @Scott_Tansley for your input and feedback. I ended up using the following configuration after coordinating with our IT department and ESRI Support. 1) The external.domain.com is passed through the external firewall on port 443 to the IIS server in the DMZ via NAT and a Web Application Firewall. The IIS server hosts the Portal and server web adapters using a CA-issued certificate for the external domain. However, the IIS server is a member of the internal domain but on a different subnet. 2) The Web Adapters were set to the external 443 port on the IIS server and configured using the external URLs https://external.domain.com/portaladaptername/webadapter and https://external.domain.com/serveradaptername/webadapter. These are pointed to the internal Portal and Server names - https://portalserver.domain.local:7443 and https://arcgisserver.domain.local:6443. 3) We set up a Split-DNS on our internal domain for external.domain.com. This directly directs the internal request to the IIS web adapters in the DMZ. The external DNS directs the external IP to our network edge where the external firewall uses NAT to the internal DMZ IP. 4) We use SSL certificates from our internal domain CA on all internal ArcGIS and Portal Servers. These were requested and installed on each server in place of the self-signed certificates. We also added our domain CA root and intermediate certificates to these servers. We could have added each server's certificate to each ArcGIS server, but this quickly gets complicated with multiple servers. The IIS server is using a commercial CA for the external domain name. 5) At this point, everything was working, and we integrated Portal using IWA. This allowed us to set up a domain administrator account on Portal before federating. All the existing services were referenced into Portal under the domain account used to federate. 6) We chose to go ahead and federate the Portal with our ArcGIS server site. We logged onto Portal using https://external.domain.com/portaladaptername/home. For the Services URL we used https://external.domain.com/serveradaptername. We have multiple ArcGIS GIS servers running on our ArcGIS Server site; therefore, the same URL was used for the Administration URL rather than one of the 6443 URLs. I missed this requirement the first time - thank goodness for hourly server snapshots. This does require Administration to be enabled on the server web adaptor. https://enterprise.arcgis.com/en/portal/latest/administer/windows/federate-an-arcgis-server-site-with-your-portal.htm
... View more
05-07-2023
03:36 PM
|
1
|
0
|
3083
|
|
POST
|
Hello All, We got Enterprise 11.1 deployed on our test platform and all our migration details worked out. However, IT announced this morning that the update of our internal domain name will not be implemented at this time. We had planned on using the same internal and external domain to facilitate the deployment of our new 11.1 Enterprise system. The web adapters were to be placed in a DMZ and the Portal and GIS Servers placed on the internal network behind the firewall. I understand the ArcGIS Enterprise portal supports only one DNS for public portal URL. Can this be set to the internal domain with internal server and portal web adapters then add a second pair of Web Adapters in the DMZ as noted below? We do not have a reverse proxy available. Modified from Deployment Patterns for Exposing ArcGIS Enterprise Secured Services to External Users How would the two additional Web Adapters be configured? I assume external.domain.com to the internal.domain.net, all on 443.
... View more
05-02-2023
11:34 AM
|
0
|
3
|
3195
|
|
POST
|
I ended up Integrating after Federating the Portal. The only downside is all the existing content on the ArcGIS Servers was assigned to the portal account used when Federating. It was not too hard to use the "Transfer Content" option on the member's list to assign the content to the appropriate domain user.
... View more
04-30-2023
05:37 PM
|
1
|
0
|
1580
|
|
POST
|
We are setting up a new multi server, 11.1 Enterprise deployment. I have my notes from our last 10.x deployment but I did not document if integration with IWA should be completed on Portal before or after federation. Does it matter?
... View more
04-28-2023
04:56 AM
|
0
|
3
|
1644
|
|
POST
|
Looks like @StefanUseldinger had the correct date on this one. Enterprise 11.1 documentation started showing up this morning and the software is available for download on my.esri download links. I guess I know what I will be building next weekend.
... View more
04-20-2023
11:50 AM
|
1
|
0
|
1202
|
|
POST
|
@DavidPike, Thanks. Yes, it looks like the MAPX is the best option. Just slow to load when there are a lot of feature classes.
... View more
04-14-2023
08:25 AM
|
0
|
0
|
4602
|
|
POST
|
Thanks, @Robert_LeClair. That is what we attempted; however, when you open the APRX file on another system or open a shortcut to the APRX file ArcGIS Pro creates the APRX, GDB and ATBX files in the folder (or desktop) where the APRX was opened. For example, I clicked on the Wards.aprx - shortcut saved on my desktop and ArcGIS Pro created the additional files.
... View more
04-14-2023
08:22 AM
|
0
|
1
|
4603
|
|
POST
|
At the end of this month, we are fully migrating to ArcGIS Pro 3.1 from Desktop 10.x. For ArcGIS Desktop 10.x, we had created about 30 MXDs that are saved on a read-only network share. Users can quickly select a needed MXD to load onto their system in ArcGIS and render the needed information. The MXDs can be accessed directly from the share or from a handful of shortcuts that are saved to the user's desktop. They can also save the MXD locally and make personal modifications as they deem necessary for their own use. Furthermore, our GIS team can make changes to the MXDs on the read-only share as changes are needed and users receive these updates the next time they open the MXD or the link to the MXD. We have not been able to find a similar means to disseminate this information in ArcGIS Pro. We did a test using APRX files but this resulted in other files being created on the user's system including GDBs, ATBX, etc. for each APRX opened. We also tried using MAPX files but with some of our larger maps, it can take some time to import all the feature classes and dataset layers when opening the MAPX file. The same using LYRX files but even slower. Any suggestions and does anyone know the recommended method to complete something similar in ArcGIS Pro?
... View more
04-14-2023
07:38 AM
|
1
|
6
|
4637
|
|
POST
|
@AdrianWelsh , With AppBuilder and Javascript API 3.x being retired in July 2024, I would use Experience Builder. You could save your chats to a database table and connect them together using a 1:M relationship class through a static Global ID on the point feature to a GUID on each chat thread. In Experience builder, you can connect widgets together using actions as outlined in the ESRI document Add and connect widgets.
... View more
03-23-2023
07:55 AM
|
1
|
0
|
1450
|
|
POST
|
Found the group. Not sure why this does not show in search. Still looking for a list of custom Experience Builder widgets. https://community.esri.com/t5/experience-builder-custom-widgets/gh-p/eb-custom-widgets
... View more
03-12-2023
08:27 AM
|
0
|
0
|
1205
|
|
POST
|
With ESRI announcing AppBuilder is being phased out next year I started looking into migrating to Experience Builder. Is there a similar user group for Custom Experience Builder Widgets and a list of those available on the ESRI Community?
... View more
03-12-2023
08:21 AM
|
1
|
1
|
1211
|
| Title | Kudos | Posted |
|---|---|---|
| 2 | 05-14-2026 12:23 PM | |
| 1 | 09-16-2019 05:49 PM | |
| 1 | 06-11-2025 03:32 PM | |
| 1 | 12-26-2023 09:15 AM | |
| 1 | 12-29-2023 10:06 AM |
| Online Status |
Offline
|
| Date Last Visited |
05-14-2026
11:20 AM
|