<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco integration with azure AD for user/group sync in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73577#M23679</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Thanks a lot Axel.&amp;nbsp; After checking carefully we found followings in share.log:&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;2019-03-05 13:59:00,062 ERROR [org.alfresco.web.site] [http-apr-8080-exec-3] javax.servlet.ServletException: SAML LogoutResponse must be submitted using POST&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;It is rather obvious exception that&amp;nbsp;after successful logout Azure AD&amp;nbsp;sends logout response to Share Logout URL, but it should have been done using POST binding.&amp;nbsp; Unfortunately I am not able to figure anyway in Azure AD&amp;nbsp;to specify POST binding.&amp;nbsp; &amp;nbsp; Just hoping if this gives some hint for you to remember how you overcame this issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Mar 2019 21:55:30 GMT</pubDate>
    <dc:creator />
    <dc:date>2019-03-14T21:55:30Z</dc:date>
    <item>
      <title>Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73572#M23674</link>
      <description>Hello everyone,We have need to integrate Alfresco with Azure AD for users/groups synchronization and authentication.&amp;nbsp; Just wondering if anyone had similar requirement and it was possible to do so.&amp;nbsp; Basically I am trying to find answer for:1) If it is possible to sync users and groups from Azure AD t</description>
      <pubDate>Tue, 15 Jan 2019 21:03:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73572#M23674</guid>
      <dc:creator />
      <dc:date>2019-01-15T21:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73573#M23675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use Azure AD just like an on-prem AD. The only thing you'd need to do is enable LDAPS access to your Azure AD, which is not enabled by default. Check the appropriate &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory-domain-services/active-directory-ds-admin-guide-configure-secure-ldap" rel="nofollow noopener noreferrer"&gt;Azure docs&lt;/A&gt;&amp;nbsp;for enabling LDAPS.&lt;/P&gt;&lt;P&gt;With Alfresco Enterprise you can setup SAML authentication with Azure AD easily. I have this running at a local customer who uses Azure AD to handle external users. Note that even without SAML as SSO, you can already authenticate against Azure once you have configured the LDAP-AD integration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 09:03:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73573#M23675</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2019-01-16T09:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73574#M23676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Axel.&amp;nbsp; Now when we have confirmation that it is possible we will figure out next steps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2019 08:22:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73574#M23676</guid>
      <dc:creator />
      <dc:date>2019-01-17T08:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73575#M23677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Axel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are finally able to configure user and group sync from Azure AD.&amp;nbsp; We are also able to setup SAML authentication against Azure AD enterprise application.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we are having slight trouble when user tries to logout.&amp;nbsp; We have configure IdP service URLs like following in Alfresco Admin console page:&lt;/P&gt;&lt;UL&gt;&lt;LI style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;IdP Authentication Request Service URL (SingleSignOnService Location from Azure AD metadata file)&lt;/LI&gt;&lt;LI style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;IdP Single Logout Request Service URL&amp;nbsp;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;SingleLogoutService Location from Azure AD metadata file)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;IdP Single Logout Response Service URL&amp;nbsp;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;SingleLogoutService Location from Azure AD metadata file)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have identical URL for all three fields in metadata file.&amp;nbsp; After logout it redirects user to&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;IMG class="image-1 jive-image" src="https://connect.hyland.com/legacyfs/online/alfresco/25526_pastedImage_1.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And after click of "&lt;STRONG&gt;Back to My Dashboard&lt;/STRONG&gt;" button it takes user to user dashboard page without any login.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if we are missing some configuration here but it seems logout is not really happening and also can we someone avoid share error page.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Rajesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 14:26:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73575#M23677</guid>
      <dc:creator />
      <dc:date>2019-03-04T14:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73576#M23678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I remember hitting a similar&amp;nbsp;error when we set this up at a customer, and it turned out we just had a configuration error in Azure config + Alfresco SAML config. Unfortunately I can't remember specifically what our mistake was, but you should check again if all the SAML login / logout URLs have been configured correctly both in Azure and Alfresco.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 21:58:17 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73576#M23678</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2019-03-04T21:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73577#M23679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Thanks a lot Axel.&amp;nbsp; After checking carefully we found followings in share.log:&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;2019-03-05 13:59:00,062 ERROR [org.alfresco.web.site] [http-apr-8080-exec-3] javax.servlet.ServletException: SAML LogoutResponse must be submitted using POST&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;It is rather obvious exception that&amp;nbsp;after successful logout Azure AD&amp;nbsp;sends logout response to Share Logout URL, but it should have been done using POST binding.&amp;nbsp; Unfortunately I am not able to figure anyway in Azure AD&amp;nbsp;to specify POST binding.&amp;nbsp; &amp;nbsp; Just hoping if this gives some hint for you to remember how you overcame this issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2019 21:55:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73577#M23679</guid>
      <dc:creator />
      <dc:date>2019-03-14T21:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73578#M23680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;B&gt;Rajesh Jha&lt;/B&gt;‌ we are blocked with the same issue you summarized. Were you able to fix the issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2019 09:30:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73578#M23680</guid>
      <dc:creator>sunnyoswal</dc:creator>
      <dc:date>2019-09-05T09:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73579#M23681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Axel. We are also facing the exact issue and are blocked. Is the fix you made anywhere documented by now ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2019 09:34:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73579#M23681</guid>
      <dc:creator>sunnyoswal</dc:creator>
      <dc:date>2019-09-05T09:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73580#M23682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately not.&amp;nbsp; We still have issue with logout.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2019 05:33:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73580#M23682</guid>
      <dc:creator />
      <dc:date>2019-09-06T05:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73581#M23683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh. If you don't mind answering, could you tell me if you still went with Azure AD SSO flow implementation and any workarounds you have in place for this logout issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Sep 2019 07:17:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73581#M23683</guid>
      <dc:creator>sunnyoswal</dc:creator>
      <dc:date>2019-09-06T07:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco integration with azure AD for user/group sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73582#M23684</link>
      <description>&lt;P&gt;Hi, we are looking into this method now for SAML SSO with Azure AD and MFA.&amp;nbsp; Wondering if any of the previous commenters from 2019 ever solved the problem with the logout issue.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 17:50:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-integration-with-azure-ad-for-user-group-sync/m-p/73582#M23684</guid>
      <dc:creator>afjaber</dc:creator>
      <dc:date>2023-03-29T17:50:09Z</dc:date>
    </item>
  </channel>
</rss>

