SAP Knowledge Base Article - Public

3600485 - SAP Signavio groups not updating when using SSO

Symptom

For a Signavio Workspace, Single Sign-On (SSO) has been enabled.
Users are able to login via SSO.

However, the Signavio Groups that have been implemented on the IdP side, are not being copied to Signavio.
Signavio Groups are implemented by configuring the IdP so that it sends the signavio_groups_v1 attribute.

Cause

Just-In-Time (JIT) provisioning has not been enabled on the Signavio Workspace.

When JIT is enabled, among other actions it will use the signavio_groups_v1 attribute contained in the SAML being passed from the IdP.
If JIT is not turned on, then the signavio_groups_v1 attribute is ignored.

Resolution

Turn on Just-In-Time (JIT) provisioning for the Signavio Workspace.

  1. In the explorer, click Setup > Manage SAP Signavio Process Collaboration Hub authentication.
  2. To enable just-in-time provisioning using SAML, select Create new user accounts automatically.
    This option also means that the signavio_groups_v1 attribute will be used, when it is passed in the SAML from the IdP.
  3. Confirm with Save settings and close the dialog.

See Also

Single Sign-on Using SAML > Enable SSO Using SAML | SAP Help Portal

Keywords

KBA , BPI-SIG-CA-SEC , Workspace Security for SAP Signavio Transformation Suite , Problem

Product

SAP Signavio Process Manager all versions