<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloudpath and Azure AD SAML Authentication with different groups in Cloudpath Enrollment System (ES)</title>
    <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44790#M472</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;My question is when using Azure AD to sign in using SAML is there a way to declare the different groups having access to a certain vlan? So that the group of IT's automatically&amp;nbsp;&amp;nbsp;end up in a certain vlan different from when a user from a different group logs on.&lt;/P&gt;</description>
    <pubDate>Mon, 16 May 2022 14:31:28 GMT</pubDate>
    <dc:creator>dennisvb</dc:creator>
    <dc:date>2022-05-16T14:31:28Z</dc:date>
    <item>
      <title>Cloudpath and Azure AD SAML Authentication with different groups</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44790#M472</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;My question is when using Azure AD to sign in using SAML is there a way to declare the different groups having access to a certain vlan? So that the group of IT's automatically&amp;nbsp;&amp;nbsp;end up in a certain vlan different from when a user from a different group logs on.&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 14:31:28 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44790#M472</guid>
      <dc:creator>dennisvb</dc:creator>
      <dc:date>2022-05-16T14:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudpath and Azure AD SAML Authentication with different groups</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44834#M473</link>
      <description>&lt;P&gt;Dennis,&lt;/P&gt;&lt;P&gt;Yes, this is possible, if you map the group claim attribute, then we can create policies with specific VLANs(or RADIUS attributes) based on those Groups.&lt;/P&gt;&lt;P&gt;In Azure, there is a limitation of getting the actual group name to come over via SAML. If they used Azure AD Connect Sync 1.2.70.0 or above and bring those groups from On-Premise AD, they will show up with the group name.&lt;/P&gt;&lt;P&gt;However, if the groups are not brought over from on-premise AD, we can still accomplish the use case but we need to filter based on the Object-ID of the group(i.e.,&amp;nbsp;c8fbf2ba-e5f4-4105-a942-481f396746b3)&lt;/P&gt;&lt;P&gt;As long as that group claim is mapped to "Group/Affliation Attribute" in SAML config on CP, then we can create a policy like this:&lt;BR /&gt;&lt;BR /&gt;IF, Group =&amp;nbsp;c8fbf2ba-e5f4-4105-a942-481f396746b3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THEN, VLAN = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you have questions on this, if you provide your e-mail I can send you some screenshots.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Pierce&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Pierce&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 16:39:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44834#M473</guid>
      <dc:creator>pierce_larsen</dc:creator>
      <dc:date>2022-05-18T16:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudpath and Azure AD SAML Authentication with different groups</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44835#M474</link>
      <description>&lt;P&gt;Dennis,&lt;BR /&gt;&lt;BR /&gt;I uploaded the screens as a ZIP file to Google Drive, let me know I can e-mail them as well:&lt;/P&gt;&lt;P&gt;&lt;A title="ZIP file with screenshot on Google Drive" href="https://drive.google.com/file/d/1YXsK4oaZMTv3g2E4jc_pIege-dZNI6_q/view?usp=sharing" target="_blank" rel="noopener"&gt;https://drive.google.com/file/d/1YXsK4oaZMTv3g2E4jc_pIege-dZNI6_q/view?usp=sharing&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Let me know if you have questions.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Pierce&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 17:01:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44835#M474</guid>
      <dc:creator>pierce_larsen</dc:creator>
      <dc:date>2022-05-18T17:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudpath and Azure AD SAML Authentication with different groups</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44851#M475</link>
      <description>&lt;P&gt;Hi Pierce,&lt;/P&gt;&lt;P&gt;It sounds clear to me. Already thank you in advance this looks like a helpful solution.&lt;BR /&gt;Will try to config it later.&lt;/P&gt;&lt;P&gt;thanks,&lt;BR /&gt;Dennis&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:59:57 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44851#M475</guid>
      <dc:creator>dennisvb</dc:creator>
      <dc:date>2022-05-19T09:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudpath and Azure AD SAML Authentication with different groups</title>
      <link>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44860#M476</link>
      <description>&lt;P&gt;Not a problem, let me know how if you need any assistance.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Pierce&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 20:40:20 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Cloudpath-Enrollment-System-ES/Cloudpath-and-Azure-AD-SAML-Authentication-with-different-groups/m-p/44860#M476</guid>
      <dc:creator>pierce_larsen</dc:creator>
      <dc:date>2022-05-19T20:40:20Z</dc:date>
    </item>
  </channel>
</rss>

