question

rikin avatar image
0 Votes"
rikin asked rikin commented

Azure AD User Auto provision in Salesforce with profile

Hi @AmanpreetSingh-MSFT

Apologies for the direct approach but I see there is a similar issues you are dealing with an I am have more or less the same issue.

I am provisioning an AAD Guest User (third party vendor), adding to AAD Security Group which is associated in Salesforce SSO and with profile (down from Salesforce to AAD).

This issue is that the User gets created AAD >> Salesforce but not with the correct profile as intended.
Am I missing any particular attribute?

Your assistance is highly appreciated.

Thanks,
Rikin

azure-ad-saml-sso
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

ZollnerD avatar image
1 Vote"
ZollnerD answered rikin commented

Are you using Salesforce's SAML JIT provisioning where a user account is created at the time of sign-in, or are you using the Azure AD User Provisioning feature under the "Provisioning" blade of a Salesforce Enterprise Application in Azure AD? It isn't clear which you are using.

If you are using SAML JIT, your question would likely be better handled by Salesforce - our service would merely provide a SAML token/assertion as configured in the SAML SSO setup in Azure AD. How that data is consumed by Salesforce to either sign in a user or potentially create a user is logic entirely owned by Salesforce.

If you are using Azure AD User Provisioning - these issues can be far more complex (and contain more personal data about the users being provisioned) than should be handled over a Microsoft Q&A post - and in that case I would strongly suggest creating a support case with Azure AD to receive assistance there.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi ZollnerD,

Many thanks for getting back.

I am not using SAML JIT for Salesforce.

I am using Azure AD User Provisioning as mentioned in you first line.

Have opened up a support ticket with Microsoft and lets see where I end up.

Thanks again.
Rikin

0 Votes 0 ·