Skip to main content
Prudhvi Keertipati
Guru
February 3, 2025
Question

PRA - AD Group Synchronization (Pre-Provisioning)

  • February 3, 2025
  • 21 replies
  • 680 views

Hi All,

In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.

Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM).

 

Thanks,

 

21 replies

Prudhvi Keertipati
Guru
February 3, 2025

Adding more context to the requirement:

We are using group policies to assign jump groups, policies and roles. Currently we are assigning the user to group policies after their account provisioned through first login.

We have one AD group where all PRA users will be member of. We want to sync and pre-provision these users to PRA and assign the Group Policies to them even before they access the PRA for the first time. 
 

Prudhvi K
Prudhvi Keertipati
Guru
February 3, 2025

In the SAML Security Provider, I added LDAP Group Lookup. but I’m not able to figure out, how this can be useful for my use case. What is the purpose of adding groups from different provider?

Prudhvi K
Rising Star
February 27, 2025

Hi Prudhvi,

 

Please make changes in the user schema in your security provider settings. Please keep complete domain while searching and you would be able to see users in the provided security provider in the group policy. Add the users in them and mark these settings as the final. 

The users will still not be visible in the user list until they login in their console. Once they login they will be assigned in their group policy.

 

Please let me know if this helped. 

 

 

 

 

Trailblazer
May 6, 2025

Is it fixed? 

 

What approach you used? ​@Prudhvi Keertipati 

 and ​@sonam 

 

Its treating AD user and SAML user differently even though they are same users?

Rising Star
May 6, 2025

HI Nazia , 

 its the way you want to authenticate these users. These are different methods, if you are authenticating through AD then you need to do the LDAP configuration and if it is SAML then you need to use SAML2 authentication. 

 

and yes they are 2 different entities. 

 

Regards,

Sonam

Trailblazer
May 6, 2025

Hi Sonam,

 

Here is my scenario.

 

  1. I Have configured AD for domain login and Ideally I should assign permissions to AD users and even though they login through SAML or do domain login they should see the assets assigned for domain account.
  2. But in this case of PRA we now how 2 users with same account one from AD an another from SAML.
  3. If user login with SAML he will not see any asset as we have assign it on AD account and not the account of SAML.

What we want to do it irrespective of users login mechanism permissions should only be through AD account.

 

Is it something doable and what configuration required.

 

As in our case if use login from outside network they will use SAML but if they login within network they will use AD login.

 

Regards,

Naziya.

Rising Star
May 6, 2025

Hi Yasmin, 

 

In either case you can create jump groups with required users to ensure that they have required systems to access.

 

Regards,

Sonam

Trailblazer
May 6, 2025

Hi Sonam,

 

My concern us really not assigning permission, my concern is why do I have to do same activity twice for same user ( we only want to have different login mechanism thats it) once login inside PRA there should be only one profile for a user.

Rising Star
May 6, 2025

HI Naziya, 

Can you please share the security provider settings. As per my understanding you must have configured two authentication mechanism. LDAP and SAML .. the users identity are completely different in both , their names may be same. but it is considering them different because one entity cannot verify from the other other. but in console you are able to see them same. but according to the console they both are different as they come from different authentication mechanism.

 

Regards,

Sonam

Trailblazer
May 6, 2025

Hi Sonam,

 

Yes we have 2 Security providers.