You are viewing limited content. For full access, please sign in.

Question

Question

No Identity Providers listed when configuring Create Directory User activity

asked on February 24

In Workflow (12.0.2510.3321) when configuring the "Create Laserfiche Directory User" activity, after configuring and selecting the "Server", when I select "SAML User" for the User Type, and select the ... button to select the Identity Provider value it comes back blank.

I have 2 Okta IdPs configured in LFDS, how do I get them to show up in this window?

0 0

Answer

SELECTED ANSWER
replied on February 25

So that would be the service user specified in the Workflow Server's service login. And as you note below, it needs to be granted rights to do whatever you're asking it to do in LFDS, including viewing objects.

1 0

Replies

replied on February 24

I'd try explicitly registering the identity provider through the Workflow Configuration Manager utility and then see if it's available to select in the activity.

0 0
replied on February 25 Show version history

That helped me narrow it down a bit. I did what you suggested on one of my Workflow servers that is on the same domain as the LFDS server and it now populates the 2 SAML IdPs.

However, on another Workflow server that is on a different domain than the LFDS server it does not. I am able to register the LFDS server as a Trustee Directory and when I click Test it is successful, but neither of the SAML IdPs show.

I checked the various logs (LFWorkflow, Application, System) on the Workflow server and nothing has been recorded.

1 0
replied on February 25

Is the trustee directory set to use Windows Authentication to LFDS?

1 0
replied on February 25

Why yes, yes it is.

0 0
SELECTED ANSWER
replied on February 25

So that would be the service user specified in the Workflow Server's service login. And as you note below, it needs to be granted rights to do whatever you're asking it to do in LFDS, including viewing objects.

1 0
replied on February 25 Show version history

It looks like in LFDS under Settings\Identity Providers\MyOktaIdP\Security I needed to add the service account that the Workflow service runs as for the server on the other domain. I can now see the Okta IdPs in the "Choose an Identity Provider" window.

Are there any other permissions that need to be added in LFDS for that account to create and delete accounts, and apply licenses?

I am thinking I may need to add security rights under the Organization in LFDS.

0 0
replied on February 25

I was correct. Here are the rights that need to be assigned in LFDS to use the various LFDS activities in Workflow:

Create Laserfiche Directory User
- Accounts\Organizations\{Organization}\Security\{User}\View
- Accounts\Organizations\{Organization}\Security\{User}\Add Objects

Assign User License in Laserfiche Directory
- Settings\Security\{User}\View Site
- Settings\Security\{User}\Assign Licenses

Assign Trustee to Grops in Laserfiche Directory Server
- Settings\Security\{User}\Modify

Create Laserfiche Directory Group
- Settings\Security\{User}\Add Objects

Delete Laserfiche Directory Trustee
- Settings\Security\{User}\Remove Objects

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.