Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Feasibility of adding Azure AD groups to Azure AD application instance from Saviynt

mkaushal
New Contributor II
New Contributor II

Hi Team,

Our Saviynt is in v23.4. Is there a feasibility of implementing the configurations on Saviynt for adding Azure AD groups to Azure AD application instance from Saviynt. If yes, can you please share the steps to achieve the same? Alternatively, if there is relevant documentation for this, please share it with me. Thanks in advance. 

Regards,

Kaushal

5 REPLIES 5

SB
Saviynt Employee
Saviynt Employee

You can manage Azure AD groups from Saviynt. Below is the link to the documentation you can refer in order to configure the same.

Configure Group Management - https://docs.saviyntcloud.com/bundle/EIC-Admin-v2021x/page/Content/Chapter07-General-Administrator/C...

Azure AD Connector doc (for JSON ref) - https://docs.saviyntcloud.com/bundle/AzureAD-v23x/page/Content/Configuring-the-Integration-for-Manag...

 


Regards,
Sahil

mkaushal
New Contributor II
New Contributor II

Hi Sahil, the ask is not to manage Azure AD groups through Saviynt. We are already doing that(creation of Azure AD Groups and addition of members to Azure AD groups). There are multiple entitlements of Azure AD such as Directory Role, Application Instance, Azure AD Group etc. Azure AD team has a manual activity where they create the Application Instance on Azure AD, and then add an Azure AD Group to it for SSO configuration. We want to see if this activity can be automated through Saviynt. I couldn't find anything in the Azure AD documentation for the same. Let me know if any other information is required.

SB
Saviynt Employee
Saviynt Employee

To be sure you want to create this new application on the existing Azure AD instance. Can you also confirm if there is an api that can be used to create the application instance.


Regards,
Sahil

mkaushal
New Contributor II
New Contributor II

Hi Sahil,

We will have a REST API for adding the AAD groups to Application Instance. If possible, we would like to achieve this config in the existing Azure AD connector. If that's not possible, we are okay with any other approach to help us achieve this functionality. 

SB
Saviynt Employee
Saviynt Employee

This is currently not supported with OOB solution.


Regards,
Sahil