| 不具合 ID 番号 |
BUG-000167760 |
| 送信されました | May 23, 2024 |
| 最終更新日 | June 17, 2025 |
| 適用対象 | Portal for ArcGIS |
| 見つかったバージョン | 11.2 |
| オペレーティング システム | Windows Server |
| オペレーティング システムのバージョン | 2022 |
| ステータス | Known Limit
開発チームによる確認後に、この問題が、Esri の管理の範囲外にあるソフトウェアの既知の制限に関するものであると判断されました。 問題の「参考情報」セクションに、さらに詳細な説明が示されていることがあります。
|
参考情報
All communication related to users and groups for SAML logins is only one way: from the SAML identity provider (IdP) to Portal for ArcGIS.
The SAML IdP must be configured to send the group attribute and value in the SAML assertion.
When manually adding users into the ArcGIS Enterprise portal through the 'Add members for organization-specific login' option and attempting to add the users into existing SAML-based groups, those users are not added into those groups. This is because no group attribute or value is being communicated between the ArcGIS Enterprise portal and the IdP.
Since it is not possible to establish a SAML connection between the IdP and the ArcGIS Enterprise portal when users are manually created, the workflow of manually adding users into existing SAML groups is a known limitation of the SAML protocol.
対処法
Log in to the ArcGIS Enterprise portal through SAML for the first time. User types and roles can be altered by the administrator, and SAML groups are to be correctly assigned on login.
Similarly, users can alter their IdP settings to communicate group information through SAML to the ArcGIS Enterprise portal through the group names rather than IDs.
再現の手順