AD user unable to log in to Orchestrator using SAML authentication

SAML Integration - AD Group Members Not Authenticating for First-Time Users


AD user is unable to log in to Orchestrator using SAML authentication, even though the AD user group is added under manage access.

Error: "User does not exist in any organization. Please reach out to your administrator and ask them to add you to an organization. (#216)"

Cause:

SAML configuration at the Host level is only intended for SSO and not for a directory integration.

In order to authenticate users should be present in the tenants.

Resolution:

  1. Integrating SAML at the tenant level allows for automatic user creation upon login.
  2. Assign them to the appropriate groups based on the Provisioning rules.

image.png