We have two domains using the same Identity provider. Is there a way to have the Just in time provisioning set up to add the users from domain A to a different GUID than Domain B or is that not possible. we have separate accounts in our Org for each of these domains and want to keep the users separated until we are able to merge the domains and change all users email.
Hello
Welcome to the DocuSign Community and thank you for posting your concerns!
I understand you are looking to configure your claimed domains to map to a specific account under your organization using a single Identity Provider.
Please note that domains cannot be mapped directly to a specific account.
You would need to use Advanced Just in Time (JIT) provisioning to handle this, but that would all be configured within the Identity Provider. You would have to configure the Identity Provider to send us the accountid and permissionprofileid in your SAML Requests. If you do that correctly, then JIT will provision the user into the account defined in that call, with the permission profile defined in that call: Just in Time Provisioning
Regarding the configuration of the above, we don’t really have any documentation as this is something that is configured in the Identity Provider (IdP) itself, and all IdP are different, so I would recommend you contact their support for assistance if needed.
Let us know if you need further assistance with this.
Best regards,
Nathaly | DocuSign Community Moderator
"Select as Best" below if you find the answer a valid solution to your issue!
Hello
If you found my response to be a useful solution to your question, please mark it as the best answer by clicking “Select as Best” to make it easier for other users to find.
Best regards,
Nathaly | DocuSign Community Moderator
"Select as Best" below if you find the answer a valid solution to your issue!
If your IdP supports such functionality, you could potentially set up JIT provisioning to differentiate users from Domain A and Domain B and assign them to different GUIDs. If not, you might need to explore other solutions or workarounds, such as manually managing the users from different domains until you are able to merge the domains and change all users’ emails.
It’s recommended to consult with your IdP’s support or documentation for specific instructions or guidance related to your scenario. If your current IdP doesn’t support this functionality, you might also consider whether switching to a different IdP that does support this functionality would be feasible for your organization.
Reply
Sign up
Already have an account? Login
You can login or register as either a Docusign customer or developer. If you don’t already have a Docusign customer or developer account, you can create one for free when registering.
Customer Login/Registration Developer Login/RegistrationDocusign Community
You can login or register as either a Docusign customer or developer. If you don’t already have a Docusign customer or developer account, you can create one for free when registering.
Customer Login/Registration Developer Login/RegistrationEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.