Expand my Community achievements bar.

Got questions about Workfront Governance? Join our upcoming Ask Me Anything session on February 12th!
SOLVED

How do I use Active Directory Security Groups to restrict access to users authenticating via SSO?

Avatar

Level 1

We have configured Workfront to use SSO and would now like to restrict the users who are allowed to get in by adding only those authorized users to a security group in our Active Directory.

How can we identify the security groups in Workfront?

Topics

Topics help categorize Community content and increase your ability to discover relevant content.

1 Accepted Solution

Avatar

Correct answer by
Employee

Hi Carver,

It sounds like you might have already gotten your answer, but just in case anyone else has the same question, here's what Support suggests.

This is something you will need to configure at your Identity Provider. Within your Active Directory, you will need to create a group who has access to the Workfront app via SSO and then add your users to that group. If you require all Workfront users to authenticate via SSO, you will want to bulk edit your list of users on the People/Users page within Workfront. You can select all users, Edit, then check the Only Allow SAML 2.0 Authentication box, then Save.

Thank you,

Kyna

View solution in original post

2 Replies

Avatar

Correct answer by
Employee

Hi Carver,

It sounds like you might have already gotten your answer, but just in case anyone else has the same question, here's what Support suggests.

This is something you will need to configure at your Identity Provider. Within your Active Directory, you will need to create a group who has access to the Workfront app via SSO and then add your users to that group. If you require all Workfront users to authenticate via SSO, you will want to bulk edit your list of users on the People/Users page within Workfront. You can select all users, Edit, then check the Only Allow SAML 2.0 Authentication box, then Save.

Thank you,

Kyna

Avatar

Level 1

Thank you. We worked with our Identity Provider to configure the security group.