Splunk AppDynamics

How do I map Group/users in Accounts Management Portal

Randy_Manipon
New Member

Just want to ask if the approach in mapping groups/users in appdynamics controller is the same in Account Portal?

I already configured the SAML federation and in azure.Then,  in Azure, I added a group and map in account portal for the SSO. However, users are still requires to to enter a password upon login. Is there something I missed? 

Labels (3)
0 Karma
1 Solution

Bill_Howard
Explorer

Hi @Randy.Manipon 

At this time, there is no grouping support for the Accounts SAML federation feature.  The current functionality is for identity authentication only.  Any user that is set to authenticate through the IDP that you have configured through the SAML federation function will be directed to your IDP for authentication.   This requires one of 2 things: 1) user is registered already in Accounts user management and set to be authenticated by your IDP or 2) user is "just in time" (JIT) provisioned into Accounts user management through the IDP initiated flow.    Once the user record is established in the Accounts user management listing, when they come to the Accounts pages or services of appd.com to login, they should get directed to your Azure IDP to authenticate.  

For reference, the documentation is here: https://docs.appdynamics.com/21.12/en/appdynamics-essentials/account-management/account-management-p...

Over time, we do aim to provide improved JIT provisioning as well as attribute mapping support to enable access control from SAML attributes.  Look for some of those improvements later this year.

Does this help?  

View solution in original post

Bill_Howard
Explorer

Hi @Randy.Manipon 

At this time, there is no grouping support for the Accounts SAML federation feature.  The current functionality is for identity authentication only.  Any user that is set to authenticate through the IDP that you have configured through the SAML federation function will be directed to your IDP for authentication.   This requires one of 2 things: 1) user is registered already in Accounts user management and set to be authenticated by your IDP or 2) user is "just in time" (JIT) provisioned into Accounts user management through the IDP initiated flow.    Once the user record is established in the Accounts user management listing, when they come to the Accounts pages or services of appd.com to login, they should get directed to your Azure IDP to authenticate.  

For reference, the documentation is here: https://docs.appdynamics.com/21.12/en/appdynamics-essentials/account-management/account-management-p...

Over time, we do aim to provide improved JIT provisioning as well as attribute mapping support to enable access control from SAML attributes.  Look for some of those improvements later this year.

Does this help?  

Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...