操作方法
当基于 Azure Active Directory (AD) 的安全声明标记语言 (SAML) 用户登录到 ArcGIS Online 或 ArcGIS Enterprise 并且为多于 150 个组的成员时,SAML 声明中将缺少该用户的组声明。 因此,该用户不会添加到 ArcGIS Online 和/或 ArcGIS Enterprise 中的任何基于 SAML 的企业组。
Azure AD 将 SAML 声明响应中可以发送的组数限制为 150。 有关详细信息,请参阅 Microsoft 文章“使用 Azure Active Directory 为应用程序配置组声明”。
Note: Due to an update to AzureAD in late 2020, this is no longer a viable workflow. The limit of 150 groups is now a hard maximum leading to renewed demands for ArcGIS Enterprise to support the Microsoft Graph API for organizations with expansive group structures. ENH-000142837: "Add support for retrieving SAML groups, when Azure AD is the SAML IDP and a user’s group membership exceeds 150." If you are affected by this limitation, please log a case with Esri Support Services and request to be added to this record.
Note: For performance and reliability, it is not recommended to send a large number of groups in the SAML assertion. A better alternative to using SAML-based enterprise groups is to use groups managed by ArcGIS Online or ArcGIS Enterprise.
使用 Azure AD 高级订阅,可以按照以下步骤将 SAML 声明响应中发送的组数从 150 增加到 500:
文章 ID: 000022190
获取来自 ArcGIS 专家的帮助
立即开始聊天