Forum Discussion
DanielNiccoli
Oct 14, 2020Iron Contributor
How To Work Around The Azure SAML Group Claim Limitations?
We recently implemented a model in which our users can create Office 365 groups, which then can be used in all our SAML-connected third-party cloud applications to grant access to resources withing t...
PeterJ_Inobits
Oct 20, 2020Iron Contributor
So you are ADFS as the IDP for these clouds apps or Azure AD? Also have you investigated claims mapping.... I'm very rusty on it but I vaguely remember being able to use it to make Azure AD supply group names in the token...
Although I suspect app roles are the longer term approach
LM
Oct 20, 2020Brass Contributor
Optional claims are only supported for groups synced from AD.
so, your options are to use groups synced from AD instead of O365 groups or use app roles
See the link below
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-group-claims?WT.mc_id=AZ-MVP-5003833#configure-the-azure-ad-application-registration-for-group-attributes