Client is asking:
Client is aware that setting up SCIM will allow them to sync Azure AD groups to LFDS. But wants to know if those groups will be available in the Laserfiche admin console and be usable for assigning access rights in Laserfiche?
Client is asking:
Client is aware that setting up SCIM will allow them to sync Azure AD groups to LFDS. But wants to know if those groups will be available in the Laserfiche admin console and be usable for assigning access rights in Laserfiche?
I believe the recommended approach would be to assign the Azure AD group to an LFDS group and then assign the LFDS group access rights in the repository.
Thank you Blake. That is what I thought I came across previously.
That's what the SCIM group synchronization integration does. It creates LFDS Laserfiche groups with the same names as the Entra groups and maps each Entra group to its matching Laserfiche group.
Thank you Sam.
Additional inquiry: Client is asking:
If we switch to using Azure AD groups for security/access rights through SCIM, will the LF License assigned to the on prem AD user still work with it or will we need to switch all licenses to SAML users?
I guess Client is asking if you can use SCIM with the Linked identity provider?
I am assuming that the whole point of using SCIM is to utilize the accounts/groups in the identity provider for account provision and access rights thereby eliminating the need to utilize the Linked identity provider.