Automatic Account ID Profile and permission profile Assignment for JIT Users Based on their Active Directory Security Group Membership
We would like to implement a configuration where user accounts in DocuSign are automatically assigned different accounts and permission profiles based on their Active Directory (AD) group membership.
Please confirm if this approach is supported with SAML/JIT provisioning setup, and if any additional configuration steps are required on either the Identity Provider or DocuSign side. We are using Entra ID as IDP.
Page 1 / 1
Hello @Harmeet.Singh
Thank you for reaching out, and welcome to the Docusign Community! We appreciate your question and assure you that we are fully committed to providing you with the best service possible.
Here is an article explaining the SAML specifications for provisioning users in accounts and permission profiles based on the AD group you are on. The Accountid (Optional): xxxxxx. The accountId must be in the account GUID format. It must be specified in conjunction with the PermissionProfileId below, or the login will fail. SAML Specifications
If you found the response to be a useful solution to your question, please “like” and mark it as the best answer by clicking “Select as Best” to make it easier for other users to find. Thank you!
Sincerely,
Ma. Cassandra | Docusign Community Moderator If this helped, feel free to Likeand click "Best Answer"
You can login or register as either a Docusign customer or developer. If you don’t already have a Docusign customer or developer account, you can create one for free when registering.
You can login or register as either a Docusign customer or developer. If you don’t already have a Docusign customer or developer account, you can create one for free when registering.