Question on setting up SAML for Author Server | Community
Skip to main content
Level 3
March 26, 2025
Solved

Question on setting up SAML for Author Server

  • March 26, 2025
  • 1 reply
  • 486 views

Hi all,

We are trying to setup SAML integration with our Author environment. As i understand, anyone who tries to login, their User account is created and added to the groups mentioned in the SAML configuration post successful authentication with IDP. Now, in case someone outside of our author group has this link and tries to access this, how can i prevent him from being added to the groups i created ?

Thanks,

Abhishek

Best answer by Saravanan_Dharmaraj

@kolluax Normally how it works is the users who wants to login to AEM Author has to apply for access  roles(Author, Approver, Admin) within the organization and get the approval for the roles and that group information will be stored in either LDAP/Active Directory. When the IDP (like Salesforce or Okta or other IDPs) authenticates the user it will look for the roles assigned for the user from the backend and return that group to AEM through SAML post back. Just because an user have access to link to IDP to login doesn't mean that user can access the author. The user has to have the actual roles assigned in the backend to make the whole thing work. Hope this helps!

1 reply

Saravanan_Dharmaraj
Community Advisor
Saravanan_DharmarajCommunity AdvisorAccepted solution
Community Advisor
March 26, 2025

@kolluax Normally how it works is the users who wants to login to AEM Author has to apply for access  roles(Author, Approver, Admin) within the organization and get the approval for the roles and that group information will be stored in either LDAP/Active Directory. When the IDP (like Salesforce or Okta or other IDPs) authenticates the user it will look for the roles assigned for the user from the backend and return that group to AEM through SAML post back. Just because an user have access to link to IDP to login doesn't mean that user can access the author. The user has to have the actual roles assigned in the backend to make the whole thing work. Hope this helps!

kolluaxAuthor
Level 3
March 26, 2025

Thanks Saravanan. I tried few things overnight and what worked for me where

1. In the SAML configs, i marked the group to be added as "everyone"

2. create a group with set ACLs and bunch of users

3. Only the users who had permissions set where able to view the pages, rest were just added to everyone group with no access to any interfaces

 

I believe this would suffice for our use-case for now. We were looking for a way to prevent them from getting to those pages/assets. Thanks for the prompt response.

 

Regards,

Abhishek