I am trying to setup an identity provider rule to assign participant licenses, but in order to access forms you must be in the Forms Access group and the option to choose a group is missing
Question
Question
Directory Server missing critical option in identity providers, impossible to assign Forms access
Answer
You don't set the LFDS group membership in the same place you set the rule synchronization (you can set rules for AD groups that do not necessarily get used in LFDS groups, and/or AD groups can belong to multiple LFDS groups).
Go to the Accounts page, select Groups, select your Forms access group, and click on the Add Directory Group button.
Replies
Is it possible you have disabled synchronization for the identity provider?
The group field in your screenshot is the active directory group that you want to sync with. In order to setup a sync that automatically assigns users you must define 3 fields.
The AD Group to sync with
The License Type
The DS Group configured for Forms Access in the Forms Config
The last required field is missing
You don't set the LFDS group membership in the same place you set the rule synchronization (you can set rules for AD groups that do not necessarily get used in LFDS groups, and/or AD groups can belong to multiple LFDS groups).
Go to the Accounts page, select Groups, select your Forms access group, and click on the Add Directory Group button.
Oh, I think I understand. Through a combination of adding a AD group to the DS group and setting up the identity providers, new AD users will be automatically setup with access to Forms.
I will give this a try when I am able to get back on the server, thanks!
This doesn't seem to sync the users in the AD group to the System Security page of Forms. It just brings in the group name instead. I set the group to a Basic User role, but the users do not show up when assigning a user task.
Oh I take that back, there is 2 sync buttons you have to select, one in forms and one in the identity providers area.
The auto-sync should start picking everything up eventually, but if you do manual sync, make sure they're listed in LFDS before running a manual sync in Forms and you should be good.
Also, since this is a new change, it would be a good idea to periodically check the sync results on the LFDS side (the ! button next to the synchronize button will show info about the last sync so you can see if it was successful).