Splunk AppDynamics

Suggestions for Role and Group configurations

CommunityUser
Splunk Employee
Splunk Employee

We are getting quite a large amount of users and groups on our controller, and we are starting to run into issues with user access. We are currently using SAML integration with Okta which is fed from our internal AD. I would like to be able to have a role for each application or group of applications and then be able to put a user into whichever AD groups represent the roles which have permissions for the apps that user needs, however it seems that the SAML integration only passes one group along, so that won't work.

I'm curious to know what others are using for their RBAC configuration who are also using AD and Okta (or perhaps another SAML provider).

Labels (3)
0 Karma
1 Solution

Pratik_Maskey
Communicator

Please refer the following document. 

https://docs.appdynamics.com/display/PRO44/SAML+Authentication#SAMLAuthentication-map_usersMappingSA...

  • Singular Group Values: The response contains an AttributeValue element with a single group-mapping value. 
  • Multiple Nested Group Values: The response contains more than one AttributeValue element, each with a single group-mapping value.
  • Singular Delimited Group Value: The response contains a single AttributeValue element with multiple, delimiter-separated group-mapping values. 
  • Regex on Singular Group Value: The response contains a single AttributeValue element from which you want to extract the group-mapping value with a regular expression.  

Hope this helps.

Thanks

View solution in original post

Pratik_Maskey
Communicator

Please refer the following document. 

https://docs.appdynamics.com/display/PRO44/SAML+Authentication#SAMLAuthentication-map_usersMappingSA...

  • Singular Group Values: The response contains an AttributeValue element with a single group-mapping value. 
  • Multiple Nested Group Values: The response contains more than one AttributeValue element, each with a single group-mapping value.
  • Singular Delimited Group Value: The response contains a single AttributeValue element with multiple, delimiter-separated group-mapping values. 
  • Regex on Singular Group Value: The response contains a single AttributeValue element from which you want to extract the group-mapping value with a regular expression.  

Hope this helps.

Thanks

Umervali_Niyama
Path Finder

Hi Michael

we have similar integration with onelogin and we were able to make users part of mutiple rolegroups\AD groups.

Apart from this I have a question , do you analytics , server monitoring , DB monitoring if yes how are you planning RBAC for each app teams?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...