SAML Directory Manager Role Attributes

Confluence User - 15 Feb, 2018

The SAML Directory Manager provides a way to specify nameId, email, first and last names, and that works fine.  Does it honor role claims (e.g., as http://schemas.microsoft.com/ws/2008/06/identity/claims/role or some variation thereof)?  We have the problem that users who are auto-provisioned via the SAML directory manager don't have any roles.

Another seemingly related problem is that the profiles of users who are auto-provisioned by the SAML directory manager can't be edited even by an admin on the system (the edit button simply doesn't show up).  And, they can't edit themselves because doing so requires entering their password, which by definition they don't have.

In an ideal world,  

  1. we would be able to edit users as an admin, whether or not they were auto-provisioned.
  2. we would set their "admin" role using #1.
  3. we would include their group membership as part of the SAML claim (using the role claim or a variation) and have that be in effect for the duration of their session.
  4. users could edit their own profiles without entering a password (unless changing their password).

But anything would be an improvement over the current situation, where we can't really do much at all with auto-provisioned users.  Thanks in advance!

 

authentication;plugins;server;saml

3


16 Feb, 2018
confluenceUser
confluenceUser

Hi, are you using a External Directory Manager in conjunction with the SAML one? The disabled editing could be due to that external directory manager being readonly (e.g. LDAP or Active Directory) which means you should edit the user in the external system instead. When I used the SAML Directory Manager with the internal user database, the Edit User does appear.

 

16 Feb, 2018
confluenceUser
confluenceUser

Thanks Anders, this sounds helpful.  I should say that we're not "intentionally" using another plugin in conjunction with SAML.  How can we figure this out?

We have other directory manager plugins installed (e.g., LDAP, Sync LDAP, Security Enhanced) but they're not marked as "uninstallable".  It seems like only one directory manager can be active at a time - but perhaps I misunderstand how that works?

Please let me know how to make sure I'm using the  SAML Directory Manager with the internal user database as you are.

Thanks!

21 Feb, 2018
confluenceUser
confluenceUser

Yes only one directory manager can be active at a time, but in the SAML Directory Manager configuration, there is an External Directory Manager page. If you did not configure that then you should be using the internal user database in which case the users should be editable. Perhaps you can share more details and screenshots of your plugin configurations.

RELATED QUESTIONS

Your answer


To answer a question you'll need an account.

Print