How can I send all groups that a user is member of in the SAML assertion?

Jaime Diegues 0 Reputation points
2024-01-08T17:18:54.9566667+00:00

Hi guys,

The SP provider sending the request to AWS that forward to ADFS - Microsoft ADFS responds with all information NameIP, UPN,evertyhting and is working.

However, I am finding an issue to send groups of the USER is a member of. The groups are Domain groups but in the SAML response only shows the group that is in the catalogue. If I create a claim ( send groups membership as a Claim) it will work as I expected but I have to map group by group and that will not be the solution.

If I map the LDAP attributes and select any of the groups that I can send ( for example= Token Groups - Unqualified names, it doesnt send the groups of that user is member of).

I have to create a claim map group to send in the SAML response. How can I get all groups for one user to send in the SAML response. The group is local domain.

Thanks,

Jaime

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,266 questions
Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,219 questions
0 comments No comments
{count} votes