Robin Harmsen Posted October 9 Share Posted October 9 For one of our configured SAML Resources within Workspace One Access we would like to send in the groups accosiated with the user. We currently use the ${groupNames} Value for this, but this will send out all groups accosiated with the user. We would like to filter this to a specific subset of potentially accosiated groups.. If there any way we are able to filter this, so we are able to only send in a subset? Quote Senior Engineer (SDDC, EUC, DBA, Applications) at the Netherlands Cancer Institute - Antoni van Leeuwenhoek Hospital (NKI-AVL) Link to comment Share on other sites More sharing options...
Employee Sascha Warno Posted October 9 Employee Share Posted October 9 There is no way to do this at the moment. It will just dump all groups associated with the user into the SAML assertion. With hundreds of groups that can make the xml quite heavy. 1 Quote Link to comment Share on other sites More sharing options...
Robin Harmsen Posted October 9 Author Share Posted October 9 Thats unfortunate.. then we will have to resort to all associated groups. Is a feature like this on the roadmap or backlog? Apart from perhaps creating a heavy XML... We want to filter the groups for a single resource so that it only gets the groups specifically for that resource, as the groups send can be used within the applications to give roles to users. And we do not want to send groups which have nothing to do with the application into it. Quote Senior Engineer (SDDC, EUC, DBA, Applications) at the Netherlands Cancer Institute - Antoni van Leeuwenhoek Hospital (NKI-AVL) Link to comment Share on other sites More sharing options...
Robin Harmsen Posted 13 hours ago Author Share Posted 13 hours ago @Sascha Warno Is anything shareable about whether this is on a roadmap or backlog Quote Senior Engineer (SDDC, EUC, DBA, Applications) at the Netherlands Cancer Institute - Antoni van Leeuwenhoek Hospital (NKI-AVL) Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.