You are viewing limited content. For full access, please sign in.

Question

Question

LFDS - SAML Identity Provider with Microsoft Graph for group retrieval

asked on May 7

Hi,

I'm struggling to get this properly setup. The documentation is not very clear on what property is responsible for what. Working with a SAML Identity Provider. We are LF 12, latest and greatest version (Laserfiche Directory Server 12 (Build 12.0.2603.369)).

We do have some users that have more than 150 groups tied to them, so we'd like to set this up so that it's able to retrieve the list of groups so that they can be associated to the proper LFDS group based on the SAML group ID (coming from Entra). Can someone explain what "Identifier property name" means, as I'm curious on how the link is done between the user logged in and Entra.

 

Then if we are pushing the group object IDs, is the proper setup to configure the LFDS group like so? (Add SAML Group with MS Entra group ID)

 

Our current MS Entra application has this configured as permissions, but not sure if there's other settings that need to be set as well (like claims)

0 0

Replies

replied on May 7

When you inspect the SAMLResponse EntraID post back to LFDSSTS, you will find something like

This attribute is telling LFDS that it should use value of "http://schemas.microsoft.com/identity/claims/objectidentifier" as the identity to query in EntraID.

(List a user's memberships (direct and transitive) - Microsoft Graph v1.0 | Microsoft Learn GET /users/{id | userPrincipalName}/transitiveMemberOf)

 

If all the groups are synced from local domain, using SID might be more convenient.

But if there are groups created in EntraID only, yes, create a Laserfiche group would work too.

0 0
replied on May 8

Ok thank you for that. Now, is there a way to debug if the call is succeeding to retrieve the list of groups? Is there a log file somewhere that shows which group IDs it retrieved? When I add the ID of one those groups that I want inside a LFDS group, I still get an access denied from the user (because I'm assuming it's not mapping correctly to my LFDS group). I think that's the part I'm missing.

 

0 0
replied on May 13

Do you have Entra configured as a Linked Provider with one or more AD domains registered in LFDS, or is it acting as a standalone SAML IDP?

0 0
replied on May 14

Just a standalone SAML IdP with SCIM 2.0 activated. We do not use AD within Laserfiche other than running a few of the services with service accounts.

0 0
replied on May 20

After login with such account, can you open /LFDSSTS/ClaimsTest page, to check if all the expected groups are listed there.

EntraID might be configured to not send all groups to LFDSSTS.

And since you enabled SCIM2.0, that might sync groups to LFDS, can you confirm that group (id: 1c0b....., name: XXXX) are not synced to LFDS?

0 0
replied on May 21

So upon visiting that page (/LFDSSTS/ClaimsTest), all the expected groups are not in there because in our MS Entra environment, we said only push the groups that are assigned to the application. So the users that should have access to the platform through the assigned groups, and only those groups are coming through the SAML token. I confirm that group in my example is not pushed to LF through SCIM.

But above this thread you said upon configuring those MS Graph settings, it should be calling the GET /users/{id | userPrincipalName}/transitiveMemberOf endpoint afterwards, which returns the full list of groups for direct membership and transitive groups of the user based on their object id.

But this is where I'm confused, what's the point of the Microsoft Graph API Settings in LFDS if it's only reading the groups coming in from the SAML response? I thought that feature was to query Microsoft Graph to pull ALL the groups from the user in Microsoft Entra and add those groups to his authentication token. Unless I'm misunderstanding what this feature is meant to do. In my example, the group (id: 1c0b.....) is part of the transitiveMemberOf endpoint results for the user, but not part of the "allowed" groups to login to Laserfiche through SAML.

Based on what I read in the documentation, my understanding was:

  • User would login through SAML provider, group memberships are sent through the claim
  • MS Graph would be called to retrieve the rest of his groups from Microsoft Entra
  • Add those group IDs to his claim
  • Match the group IDs to those SAML groups configured in LFDS to determine which LFDS groups he's eligible to

 

If you can clarify what the flow is and how to debug if the API call to MS Graph is actually happening, that would be appreciated! Thanks.

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.