<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Azure SAML configuration: Why is a link to the Graph API endpoint returned instead of a group list? in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Azure-SAML-configuration-Why-is-a-link-to-the-Graph-API-endpoint/ta-p/236267</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;The number of user groups that Azure Active Directory adds to a &amp;nbsp;&lt;A href="http://SAML token is limited to 150" target="_self"&gt;SAML token is limited to 150&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;If this limit is exceeded, a link to the Graph API endpoint is returned instead of a group list. Dynatrace doesn’t support retrieving user groups this way, because it would require additional authentication between Dynatrace and Azure AD.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;If you exceed the 150 limit, consider one of the following options:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Limit the number of groups that users are assigned to.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt; Configure Azure AD to send only groups assigned to the application.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Additionally, configure &lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/manage-users-groups-with-scim" target="_self"&gt;SCIM&lt;/A&gt;&amp;nbsp;for group management and user-group assignment.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 13 Feb 2024 08:35:10 GMT</pubDate>
    <dc:creator>MalcolmDavidson</dc:creator>
    <dc:date>2024-02-13T08:35:10Z</dc:date>
    <item>
      <title>Azure SAML configuration: Why is a link to the Graph API endpoint returned instead of a group list?</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Azure-SAML-configuration-Why-is-a-link-to-the-Graph-API-endpoint/ta-p/236267</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;The number of user groups that Azure Active Directory adds to a &amp;nbsp;&lt;A href="http://SAML token is limited to 150" target="_self"&gt;SAML token is limited to 150&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;If this limit is exceeded, a link to the Graph API endpoint is returned instead of a group list. Dynatrace doesn’t support retrieving user groups this way, because it would require additional authentication between Dynatrace and Azure AD.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;If you exceed the 150 limit, consider one of the following options:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Limit the number of groups that users are assigned to.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt; Configure Azure AD to send only groups assigned to the application.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Additionally, configure &lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/manage-users-groups-with-scim" target="_self"&gt;SCIM&lt;/A&gt;&amp;nbsp;for group management and user-group assignment.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Feb 2024 08:35:10 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Azure-SAML-configuration-Why-is-a-link-to-the-Graph-API-endpoint/ta-p/236267</guid>
      <dc:creator>MalcolmDavidson</dc:creator>
      <dc:date>2024-02-13T08:35:10Z</dc:date>
    </item>
  </channel>
</rss>

