SAP Knowledge Base Article - Public

3160226 - Group management in SAML for Azure AD

Symptom

We have not been able to set up the assignment of multiple groups via the Group Claims. Only one of the groups is ever handed over.

Resolution

If you are using the claim conditions in Azure AD, the behavior is expected as Azure AD is only sending the latest valid value and not all valid values as AttributeValues.

Since the version 16.10 we introduced a new attribute for Azure AD customers. With the attribute "signavio_groups_v1_azure" you can send over multiple groups, that are comma-separated. 

Keywords

process-manager, spm, sap-signavio, SAML, azure-ad, sso , KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , How To

Product

SAP Signavio Process Manager all versions ; Signavio Process Manager all versions