Esri / idp

This repository hosts the third party IDP documentation
Apache License 2.0
18 stars 6 forks source link

Configure Google Workspace SAML IDP documentation does not describe how to add an attribute to carry email addresses over into ArcGIS Online #5

Open mariahabney opened 2 years ago

mariahabney commented 2 years ago

The Esri documentation for how to configure a SAML IDP using Google Workspace does not include steps to pass in email addresses to ArcGIS Online, which is crucial when setting up a log in for administrators, even though it is mentioned previously in the documentation that ArcGIS Online supports this.

When following the steps outlined in this documentation, the users will not have email addresses associated with their account, meaning that they cannot be Administrative Contacts and may see issues when attempting to change organization administrators to an account associated with this SAML IDP.

Esri documentation for setting up other SAML providers include steps for mapping givenName, surName, and mail attributes (examples: NetIQ Access Manager and Okta), but the Google Workspace documentation does not.

The steps to Add a Custom Attribute, fill out that Attribute for the user, and then add the Custom Attribute to the SAML attribute mapping are outlined in the steps below: