Skip to main content
Question

Regarding SAML JIT group provisioning, can you please clarify system behaviour:- when are existing members cleared from a group?- will SSO users remain in groups where no claim is presented?- is it possible to revert a group to manual management?

  • November 24, 2022
  • 2 replies
  • 3 views

Same questions expanded:

- after the first SSO user presents a claim for a group, are all existing group members removed at once?

- will SSO users remain members of groups where no claim has been presented?

- to revert to manual management of a group, is it enough to stop presenting that group as a SAML claim? i.e. can we immediately populate groups manually again, or some other action required first?

2 replies

Hi Rohan, Thank you for reaching out! Did you have time to check the below documentation regarding your questions: https://docs.celonis.com/en/automated-user-and-group-provisioning.html https://docs.celonis.com/en/team-settings-release-notes.html#UUID-c424cc99-f14b-606b-a3f5-eb6733cbabb8 https://docs.celonis.com/en/user-locking-policy.html Please reach out to by creating a case if you have any further questions Best regards, Rrezarta

  • Author
  • Level 1
  • December 2, 2022
Hi Rohan, Thank you for reaching out! Did you have time to check the below documentation regarding your questions: https://docs.celonis.com/en/automated-user-and-group-provisioning.html https://docs.celonis.com/en/team-settings-release-notes.html#UUID-c424cc99-f14b-606b-a3f5-eb6733cbabb8 https://docs.celonis.com/en/user-locking-policy.html Please reach out to by creating a case if you have any further questions Best regards, Rrezarta

Thanks, I did not see the Team Settings Release Notes previously.

The documentation implies that groups are matched with the SAML claim name, so that existing groups will become "managed", and non-existing groups will be created. From that, I understand that SSO users will remain in a Celonis group, as long as no other user presents a claim for that group.

What is not explicit is if the SAML <-> Celonis groups are matched only by text name, and if I can therefore simply rename the Celonis group to quickly enable/disable SAML JIT management of that group.

 

The goal is to know if I can incrementally apply and roll-back SAML JIT management myself, or if I will need assistance from Celonis.