<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Azure authentication in Product Forum</title>
    <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73282#M25887</link>
    <description>&lt;P&gt;Hi Jesus,&lt;BR /&gt;&lt;BR /&gt;Sorry I'm not an expert in AD authentication/configuration. Though looking at the &lt;A href="https://bpdocs.blueprism.com/decipher-2-2/en-us/Guides/saml-adfs/saml-adfs.htm?tocpath=Installation%7CActive%20Directory%20authentication%20through%20AD%20FS%7C_____0#Exportthetokensigningcertificate"&gt;installation instructions&lt;/A&gt; it could be something to do with the token-signing certificate. I would ask your respective AD/IT Engineer to double check this configuration.&lt;BR /&gt;&lt;BR /&gt;If everything looks as it should, you can raise a support ticket. Though if it's an issue specific to it being Azure AD, we may not be able to help as it's not currently supported.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Ben Lyons&lt;BR /&gt;Senior Product Specialist - Decipher&lt;BR /&gt;SS&amp;amp;C Blue Prism&lt;BR /&gt;UK based&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
    <pubDate>Thu, 18 May 2023 12:24:00 GMT</pubDate>
    <dc:creator>Ben.Lyons1</dc:creator>
    <dc:date>2023-05-18T12:24:00Z</dc:date>
    <item>
      <title>Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73279#M25884</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN jsaction="agoMJf:PFBcW;MZfLnc:P7O7bd;nt4Alf:pvnm0e,pfE8Hb,PFBcW;B01qod:dJXsye;H1e5u:iXtTIf;lYIUJf:hij5Wb;bmeZHc:iURhpf;Oxj3Xe:qAKMYb,yaf12d" jsname="txFAF" class="jCAhz ChMk0b" jscontroller="Gn4SMb"&gt;&lt;SPAN class="ryNqvb" jsaction="click:E6Tfl,GFf3ac,tMZCfe; contextmenu:Nqw7Te,QP7LD; mouseout:Nqw7Te; mouseover:E6Tfl,c2aHje" jsname="W297wb"&gt;Decipher 2.2 allows AD FS authentication via SAML, Is authentication with Azure AD allowed via this setup?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN jsaction="agoMJf:PFBcW;MZfLnc:P7O7bd;nt4Alf:pvnm0e,pfE8Hb,PFBcW;B01qod:dJXsye;H1e5u:iXtTIf;lYIUJf:hij5Wb;bmeZHc:iURhpf;Oxj3Xe:qAKMYb,yaf12d" jsname="txFAF" class="jCAhz ChMk0b" jscontroller="Gn4SMb"&gt;&lt;SPAN class="ryNqvb" jsaction="click:E6Tfl,GFf3ac,tMZCfe; contextmenu:Nqw7Te,QP7LD; mouseout:Nqw7Te; mouseover:E6Tfl,c2aHje" jsname="W297wb"&gt;Is it known if Blue Prism has plans to include authentication via Azure AD or LDAP?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Jesus Castellanos&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 16 May 2023 08:30:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73279#M25884</guid>
      <dc:creator>jcastellanosm</dc:creator>
      <dc:date>2023-05-16T08:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73280#M25885</link>
      <description>&lt;P&gt;Hi Jesus,&lt;BR /&gt;&lt;BR /&gt;Theoretically Azure AD can be configured using this method, providing the persons configuring it have the necessary experience and expertise with the respective AD elements. We are limited with how many different AD configurations we can reasonably test due to the sheer volume of potential set ups, so we weren't able to confirm support for it with the 2.2 release. However, I've heard examples of Decipher being configured with Azure AD, unfortunately I don't have any further details.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="10298.png"&gt;&lt;img src="https://community.blueprism.com/t5/image/serverpage/image-id/10467iBF27A0B1475BD6FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="10298.png" alt="10298.png" /&gt;&lt;/span&gt;&lt;BR /&gt;At this time it is not in the roadmap to provide AD support via LDAP.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Ben Lyons&lt;BR /&gt;Senior Product Specialist - Decipher&lt;BR /&gt;SS&amp;amp;C Blue Prism&lt;BR /&gt;UK based&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 16 May 2023 10:14:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73280#M25885</guid>
      <dc:creator>Ben.Lyons1</dc:creator>
      <dc:date>2023-05-16T10:14:00Z</dc:date>
    </item>
    <item>
      <title>RE: Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73281#M25886</link>
      <description>&lt;P&gt;We're trying to configure Azure AD and the following error occurs in return URL page &lt;A href="https://decipher.local/Account/SsoLogin" target="test_blank"&gt;https://decipher.local/Account/SsoLogin&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Any &lt;SPAN&gt;suggestion&lt;/SPAN&gt;?&lt;/P&gt;
&lt;H1&gt;Error.&lt;/H1&gt;
&lt;H2&gt;An error occurred while processing your request.&lt;/H2&gt;
&lt;DIV class="error-details"&gt;Please contact an administrator!&lt;/DIV&gt;
&lt;DIV class="error-actions"&gt;&lt;A href="https://decipher.local/" class="btn btn-primary btn-lg" target="_blank" rel="noopener"&gt;&lt;SPAN class="glyphicon glyphicon-home"&gt;&lt;/SPAN&gt;Take Me Home&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blueprism.com/" class="btn btn-default btn-lg" target="_blank" rel="noopener"&gt;&lt;SPAN class="glyphicon glyphicon-envelope"&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Contact Support&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;H3&gt;HttpAntiForgeryException&lt;/H3&gt;
&lt;PRE&gt;                                The required anti-forgery form field "__RequestVerificationToken" is not present.
                                &lt;/PRE&gt;
&lt;P&gt;thrown in Account SsoLogin&lt;/P&gt;
&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Jesus Castellanos&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Thu, 18 May 2023 11:40:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73281#M25886</guid>
      <dc:creator>jcastellanosm</dc:creator>
      <dc:date>2023-05-18T11:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73282#M25887</link>
      <description>&lt;P&gt;Hi Jesus,&lt;BR /&gt;&lt;BR /&gt;Sorry I'm not an expert in AD authentication/configuration. Though looking at the &lt;A href="https://bpdocs.blueprism.com/decipher-2-2/en-us/Guides/saml-adfs/saml-adfs.htm?tocpath=Installation%7CActive%20Directory%20authentication%20through%20AD%20FS%7C_____0#Exportthetokensigningcertificate"&gt;installation instructions&lt;/A&gt; it could be something to do with the token-signing certificate. I would ask your respective AD/IT Engineer to double check this configuration.&lt;BR /&gt;&lt;BR /&gt;If everything looks as it should, you can raise a support ticket. Though if it's an issue specific to it being Azure AD, we may not be able to help as it's not currently supported.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Ben Lyons&lt;BR /&gt;Senior Product Specialist - Decipher&lt;BR /&gt;SS&amp;amp;C Blue Prism&lt;BR /&gt;UK based&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Thu, 18 May 2023 12:24:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73282#M25887</guid>
      <dc:creator>Ben.Lyons1</dc:creator>
      <dc:date>2023-05-18T12:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73283#M25888</link>
      <description>&lt;P&gt;Hi Ben,&lt;BR /&gt;&lt;BR /&gt;After importing the Saml2 XML in Azure AD, the &lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;A href="https://decipher.url/Account/SsoLogin" target="_blank" rel="noopener"&gt;https://decipher.url/Account/SsoLogin&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; return url page gives us this other error:&amp;nbsp;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;"&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; color: #a94442; background: #F2DEDE; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;Account does not have any user permissions associated with this application.&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;". We already created the AD Group in Decipher IDP as described in the configuration guide of Saml ADFS Authentication.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language: EN-US;"&gt;In Decipher Web Server Log can be seen the following trace:&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="language-markup"&gt;&lt;CODE&gt;2023-05-24 12:18:32.9103 DEBUG [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1 Session_Start
2023-05-24 12:18:32.9103 DEBUG [12] Authenticating with SAML. Examining claims receved from the IdP...
2023-05-24 12:18:32.9103 DEBUG [12] All claims received: &lt;A href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name:" target="test_blank"&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name:&lt;/A&gt; 
2023-05-24 12:18:32.9103 INFO [12] Session: ahxwx0aixdys5yv3zzhjqeh1 Looking for claim: &lt;A href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" target="test_blank"&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn&lt;/A&gt;
2023-05-24 12:18:32.9103 INFO [12] Session: ahxwx0aixdys5yv3zzhjqeh1 &lt;A href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn" target="test_blank"&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn&lt;/A&gt; claim not present. Trying with NameIdentifier claim instead...
2023-05-24 12:18:32.9103 INFO [12] Session: ahxwx0aixdys5yv3zzhjqeh1 Username found: 
2023-05-24 12:18:32.9103 INFO [12] Session: ahxwx0aixdys5yv3zzhjqeh1 Username used for the Service Provider: 
2023-05-24 12:18:32.9103 INFO [12] Session: ahxwx0aixdys5yv3zzhjqeh1 Logging in to the server...
2023-05-24 12:18:32.9103 INFO [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1 trying to log in to the server...
2023-05-24 12:18:32.9103 DEBUG [12] Trusted login details from IdP -&amp;gt; UserName:; UserGroups: 
2023-05-24 12:18:32.9103 DEBUG [12] Trusted login start...
2023-05-24 12:18:33.1513 DEBUG [12] Logged in with the master user - OK
2023-05-24 12:18:33.1583 DEBUG [12] User  does not exist.
2023-05-24 12:18:33.1583 DEBUG [12] None of the groups provided by the IdP exists. Access not granted from the IdP, possibly access revoked before a successful login
2023-05-24 12:18:33.1583 INFO [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1 ManagerCommunication.Logout
2023-05-24 12:18:33.1583 INFO [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1, ManagerCommunication.Logout - TCP session exists
2023-05-24 12:18:33.1583 DEBUG [12]   Only TCP session exists.
2023-05-24 12:18:33.1713 INFO [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1, ManagerCommunication.Logout - Logged out!
2023-05-24 12:18:33.1713 ERROR [12] SessionID: ahxwx0aixdys5yv3zzhjqeh1, Exception: SsiServerCommunication.SsiClientSessionException: Account does not have any user permissions associated with this application
   at Ssi.Communication.TCPCommunication.TrustedLogin.Login()
   at Ssi.Communication.TCPCommunication.TCPCommunication.TrustedLogin(String userName, List`1 userGroups)
   at Ssi.Communication.ManagerCommunication.ManagerCommunication.Login(String sessionId, String userName, String password, String ssiIpAddress, Int32 ssiPortNumber, Boolean trusted, List`1 userGroups)
   at Ssi.Logic.Communication.AccountLogic.LoginWithResult(String sessionId, String userName, String password, String subdomain, Boolean trusted, List`1 userGroups)
   at Ssi.Web.Controllers.AccountController.SsoLogin(LoginViewModel model, String returnUrl)
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;As can be seen, no UserName and UserGroups are found, and None of the groups provided by the IdP exists &lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;despite of they're already created.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="lRu31"&gt;&lt;SPAN class="HwtZe" jsaction="mouseup:Sxi9L,BR6jm; mousedown:qjlr0e" jsname="jqKxS" lang="en"&gt;&lt;SPAN jsaction="agoMJf:PFBcW;MZfLnc:P7O7bd;nt4Alf:pvnm0e,pfE8Hb,PFBcW;B01qod:dJXsye;H1e5u:iXtTIf;lYIUJf:hij5Wb;bmeZHc:iURhpf;Oxj3Xe:qAKMYb,yaf12d" jsname="txFAF" class="jCAhz ChMk0b" jscontroller="Gn4SMb"&gt;&lt;SPAN class="ryNqvb" jsaction="click:E6Tfl,GFf3ac,tMZCfe; contextmenu:Nqw7Te,QP7LD; mouseout:Nqw7Te; mouseover:E6Tfl,c2aHje" jsname="W297wb"&gt;&lt;SPAN&gt;Please tell us if you have any suggestion that can help us. I have created a Blue Prism support ticket (255939) with more details.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="ZSCsVd"&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Jesus Castellanos&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Wed, 24 May 2023 10:51:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73283#M25888</guid>
      <dc:creator>jcastellanosm</dc:creator>
      <dc:date>2023-05-24T10:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: Azure authentication</title>
      <link>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73284#M25889</link>
      <description>&lt;P&gt;Hi Jesus,&lt;BR /&gt;&lt;BR /&gt;Thanks for raising the ticket, I'm working with the support engineer and he'll be in touch.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Ben Lyons&lt;BR /&gt;Senior Product Specialist - Decipher&lt;BR /&gt;SS&amp;amp;C Blue Prism&lt;BR /&gt;UK based&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Wed, 24 May 2023 12:28:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Product-Forum/Azure-authentication/m-p/73284#M25889</guid>
      <dc:creator>Ben.Lyons1</dc:creator>
      <dc:date>2023-05-24T12:28:00Z</dc:date>
    </item>
  </channel>
</rss>

