How to Migrate to New SAML IdP
search cancel

How to Migrate to New SAML IdP

book

Article ID: 401391

calendar_today

Updated On:

Products

DX SaaS

Issue/Introduction

Have our DX OO SaaS environment integrated with a SAML IdP. Required to move that to a new IdP (Azure ADFS) before the old SAML IdP is shut down.  When I look at the existing integration, there is no obvious way to modify the existing integration.

Resolution

Deleting an existing SAML integration and replacing with another SAML config provides all the same groups as the previous saml configuration will provide the desired swap-out and swap-in result.

To swap-out the existing saml1, a saml1->local conversion must be performed.  After that, the local->saml2 (for the new IdP) needs to be performed. In general, this should be performed as soon as possible (within the same login session) so the Tenant Admin role from saml1 will exist for saml2 creation.  Be sure to have all the new SAMLapp configured correctly and tested via the IdP's testing capabilities to confirm that the SAML app is populating the groups in the SAML Response for use by DXO2 on login.