2 Replies Latest reply on May 11, 2017 8:04 PM by JoshuaPaul

    how to get azure ad activedirectory groups working?

    JoshuaPaul

      i got oauth working for user accounts for aws google and microsoft

       

      but i want groups working

       

      i first used group name like regular ad

       

      and then saw it wants group id so used the super long group id but it still fails

       

      any one get it working?

        • 1. Re: how to get azure ad activedirectory groups working?
          User24245

          Hi,

           

          It worked ! But I'm not sure if it's correct solution or not..

          Please refer following URL, and set up carefully.

          http://www.dushyantgill.com/blog/2014/12/10/authorization-cloud-applications-using-ad-groups/

           

          [ Point ]

           

          1. Required Azure AD Group Object ID for FileMaker security group account.

          * Sorry for my Japanese screen capture

          security.png

          2. Perhaps, Required Azure AD Premium Plan in order to "User and Group" function.

           

          3. Set up Azure AD on "CLASSIC PORTAL" for your application.

           

          Azure AD -> Default Directory -> Your Application Name (in my case "FileMaker1") -> User and Group ->  Select Group -> Assign (Add)

           

          set-group.jpg

           

          4. Confirm user list again your account as group account

          user group.png

           

          5. Download Manifest and Locate the “groupMembershipClaims” setting. Set its value to either “SecurityGroup” or “All”. I chose "SecurityGroup".

           

          6. Upload Manifest

           

          7. Then, I can use azure ad group base authorization.

           

          Thanks.

          1 of 1 people found this helpful
          • 2. Re: how to get azure ad activedirectory groups working?
            JoshuaPaul

            Thank you!

             

            1. one of our developer is also japanese - no need to apologize!

             

            2. no need to have Premium Account - the free plan works fine

             

            3. your steps worked great!

             

            from:

             

              "groupMembershipClaims": "",

             

            to:

              "groupMembershipClaims": "SecurityGroup",

             

            and it worked!