Citrix Cloud SAML Identity Provider Attributes - Are all attributes required?

Citrix Cloud SAML Identity Provider Attributes - Are all attributes required?

book

Article ID: CTX564361

calendar_today

Updated On:

Description

Requirement to set up SAML as an Identity provider within Citrix Cloud.
One of the prerequisites is as follows: Before enabling SAML authentication, you must integrate your on-premises AD with your SAML provider. This integration allows the SAML provider to pass the following required AD user attributes to Citrix Cloud in the SAML assertion: objectSID (SID) objectGUID (OID) userPrincipalName (UPN) Mail (email) .

Need to know if all attributes are needed as some attributes may not be synced to the IDP (identity provider).

Resolution

 All fields are required from our end to use SMAL:

  • SID/UPN required for DaaS to function. 
  • Email is required for Sharefile (Needs to be imputed even if Sharefile is not in use)
  • OID is used for various other services on our backend . 

 

It is not possible to use SAML without setting these values.


Problem Cause

Configuration query as not all attributes may be synced on the identity provider