Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

A user may belong to multiple AD groups. This guide describes how to return the list of groups the user belongs to in a SAML attribute.

Section
bordertrue


Column

Under SSO>Service Providers locate the SP you wish to add the attribute to.


Click on the Ellipses and select Edit from the drop-down menu that appears


Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px



...

Section
bordertrue


Column

Add the following parameters:

FieldValue
Location:HTTP Body
Name:This can be any name the SP requires however usually it is '
Groups
groups'
Format: attrname-format:
URI
unspecified
Script:groups
*
?.name


Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Modified

Section
bordertrue
Column

Click: Install and let it run through...

Column
width60%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px
Image Removed



Remember to Save the changes

Please Test

Section
bordertrue


Column

Click: Finish

Column
width60%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

 Image Removed

Following installation of the Chisel Agent please check the following:

Section
bordertrue
Column

Check the DualShield Computer Logon Agent service is still runningHere are the groups that the AD account belongs to..



Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added




Section
bordertrue


Column
Make sure

If you log onto the SAML website  you can

browse to C:\Program Files\Deepnet Security\ComputerLogonAgent\addon\dualcs  and you can see the following files inside the folder

check to see if all the groups of which the AD account is a member of, are returned in the 'groups' attribute, by looking at the full SAML assertion...


Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed Image Added




Section
bordertrue


Column
Launch Task Manager and check for a process called dualcs.exe

In this example, this is what the SAML test page returns..


Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed Image Added