cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Not a customer? Start a free trial

Click the Start a free trial link to start a 15-day SaaS trial of our product and join our community as a trial user. If you are an existing customer do not start a free trial.

AppDynamics customers and established members should click the sign in button to authenticate.

Controller (SaaS, On Premises)

Suggestions for Role and Group configurations

SOLVED
Michael.Breed
Creator

Suggestions for Role and Group configurations

We are getting quite a large amount of users and groups on our controller, and we are starting to run into issues with user access. We are currently using SAML integration with Okta which is fed from our internal AD. I would like to be able to have a role for each application or group of applications and then be able to put a user into whichever AD groups represent the roles which have permissions for the apps that user needs, however it seems that the SAML integration only passes one group along, so that won't work.

 

I'm curious to know what others are using for their RBAC configuration who are also using AD and Okta (or perhaps another SAML provider).

By replying you agree to the Terms and Conditions of the AppDynamics Community.
Suggestions for Role and Group configurations
2 REPLIES 2
Pratik.Maskey
AppDynamics Team

Please refer the following document. 

https://docs.appdynamics.com/display/PRO44/SAML+Authentication#SAMLAuthentication-map_usersMappingSA...

  • Singular Group Values: The response contains an AttributeValue element with a single group-mapping value. 
  • Multiple Nested Group Values: The response contains more than one AttributeValue element, each with a single group-mapping value.
  • Singular Delimited Group Value: The response contains a single AttributeValue element with multiple, delimiter-separated group-mapping values. 
  • Regex on Singular Group Value: The response contains a single AttributeValue element from which you want to extract the group-mapping value with a regular expression.  

Hope this helps.

 

Thanks



Found something helpful? Click the Accept as Solution button to help others find answers faster.
Liked something? Click the Thumbs Up button.

Hi Michael

 

we have similar integration with onelogin and we were able to make users part of mutiple rolegroups\AD groups.

Apart from this I have a question , do you analytics , server monitoring , DB monitoring if yes how are you planning RBAC for each app teams?