Symptom
When my users login via SSO they are unassigned from the user groups I manually assigned them too in Explorer.
Environment
SAP Signavio Process Manager 3.0
Reproducing the Issue
- Click on your SSO link.
- Once logged in, navigate to Explorer.
- Click 'Setup'.
- From the dropdown, select the Manage users & access rights.
- Click on the User group tab
- Click on the group you should be assigned too.
- See that you are not included in the list of users.
Cause
Your users are being removed from the user groups you manually assigned them too when they login via SSO as the SAML response your idP is sending Signavio incudes in its claim, user groups the users should be assigned too. Each time the user logs in via SSO the user groups are being replaced.
Resolution
In order to avoid this you will need to include in your idP user groups attributes, the user groups you are manually assigning these users too.
See Also
For more information on user groups in SAML, please read the following excerpt from our user guide: https://documentation.signavio.com/suite/en-us/Content/process-manager/userguide/workspace-admin/manage-users/enable-sso.htm?#ConfigureyourIdP
Keywords
process, manager, user, group, saml, sso, link, assign, manual, over, written, un, assign , KBA , BPI-SIG-CA-SEC , Workspace Security for SAP Signavio Transformation Suite , Problem