<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynatrace SAAS SSO with Microsoft Azure - using claims/groups.link in Cloud platforms</title>
    <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127386#M1485</link>
    <description>&lt;P&gt;According to this part of documentation:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/23659-1582188659550.png" /&gt;&lt;/P&gt;&lt;P&gt;this will not work. &lt;A rel="noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer" href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/" target="_blank"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/&lt;/A&gt; You're limited to 150 groups.&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2020 08:51:24 GMT</pubDate>
    <dc:creator>skrystosik</dc:creator>
    <dc:date>2020-02-20T08:51:24Z</dc:date>
    <item>
      <title>Dynatrace SAAS SSO with Microsoft Azure - using claims/groups.link</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127385#M1484</link>
      <description>&lt;P&gt;Microsoft Azure returns the group claim in the SAML using an attribute&lt;/P&gt;
&lt;P data-unlink="true"&gt;http://schemas.microsoft.com/claims/groups.link&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This happens when the number of groups is very high.&lt;/P&gt;
&lt;P&gt;Can Dynatrace handle this scenario.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Eg (with groups.link): - Unable to do SSO with Dyantrace SAAS&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;lt;Attribute Name="http://schemas.microsoft.com/claims/groups.link"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;AttributeValue&amp;gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;https://graph.windows.net/48d6943f-580e-40b1-a0e1-c07fa3707873/users/ba9b7081-e2a8-4427-9cdc-92afd7099833/getMemberObjects&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;/AttributeValue&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;lt;/Attribute&amp;gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I am able to successfully do SSO when the groups are returned as in &lt;STRONG&gt;identity/claims/groups, &lt;/STRONG&gt;but not in the above scenario&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Eg (with /claims/groups list) - This works for me&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 15px; font-family: Calibri, sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; text-decoration: none; background-color: #ffffff;" data-unlink="true"&gt;&amp;lt;AttributeName="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups&amp;nbsp;"&amp;gt;&lt;BR /&gt;&amp;lt;AttributeValue&amp;gt;a8c55d9b-fdc6-4fe3-9d56-af0f87419f2c&amp;lt;/AttributeValue&amp;gt;&lt;BR /&gt;&amp;lt;AttributeValue&amp;gt;4604c7b6-57ca-4aa8-9a0b-235f4c9a3651&amp;lt;/AttributeValue&amp;gt;&lt;BR /&gt;&amp;lt;AttributeValue&amp;gt;aa312f9f-c0ab-4e65-9bbb-07503792bdd8&amp;lt;/AttributeValue&amp;gt;&lt;/P&gt;
&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 15px; font-family: Calibri, sans-serif; color: #000000; font-style: normal; font-weight: normal; text-align: start; text-indent: 0px; text-decoration: none;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 14:40:28 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127385#M1484</guid>
      <dc:creator>ashish_jamthe1</dc:creator>
      <dc:date>2024-01-15T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace SAAS SSO with Microsoft Azure - using claims/groups.link</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127386#M1485</link>
      <description>&lt;P&gt;According to this part of documentation:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/23659-1582188659550.png" /&gt;&lt;/P&gt;&lt;P&gt;this will not work. &lt;A rel="noopener noreferrer noopener noreferrer noopener noreferrer noopener noreferrer" href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/" target="_blank"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/&lt;/A&gt; You're limited to 150 groups.&lt;/P&gt;&lt;P&gt;Sebastian&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 08:51:24 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127386#M1485</guid>
      <dc:creator>skrystosik</dc:creator>
      <dc:date>2020-02-20T08:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace SAAS SSO with Microsoft Azure - using claims/groups.link</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127387#M1486</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://answers.dynatrace.com/users/15061/view.html" nodeid="15061"&gt;@Sebastian K.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;From talking to Dynatrace, I think we have following two solution options. I am yet to try either of them, will share progress with the community.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Configure Azure AD to send only security groups.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;   &lt;A href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/#expand-369example-add-group-attribute-to-saml"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/user-management-and-sso/manage-users-and-groups-with-saml/saml-azure/#expand-369example-add-group-attribute-to-saml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2. &lt;STRONG&gt;Use application roles rather than groups.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This limits the amount of information that needs to go into the token, is more secure, and separates user assignment from app configuration.&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;    &lt;A rel="nofollow noopener noreferrer noopener noreferrer" href="https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-group-claims#options-for-applications-to-consume-group-information" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-group-claims#options-for-applications-to-consume-group-information&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Change the Security group claim attribute. Something like this:&lt;/P&gt;&lt;P&gt;Before: &lt;A rel="nofollow noopener noreferrer noopener noreferrer" href="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups" target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups&lt;/A&gt;&lt;BR /&gt;After: &lt;A rel="nofollow noopener noreferrer noopener noreferrer" href="http://schemas.microsoft.com/ws/2008/06/identity/claims/role" target="_blank"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/role&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 00:33:09 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-SAAS-SSO-with-Microsoft-Azure-using-claims-groups-link/m-p/127387#M1486</guid>
      <dc:creator>ashish_jamthe1</dc:creator>
      <dc:date>2020-02-21T00:33:09Z</dc:date>
    </item>
  </channel>
</rss>

