Oracle Access Manager 11g R2PS3 (OAM 11.1.2.3) Federation Group Response Attribute Is Returned as NULL With Active Directory User Store
(Doc ID 2483400.1)
Last updated on SEPTEMBER 06, 2023
Applies to:
Oracle Access Manager - Version 11.1.2.3.0 and laterInformation in this document applies to any platform.
Oracle is not responsible for instructions/information from 3rd party sites that may be contained in this KM note.
Symptoms
Oracle Access Manager 11g R2PS3 (OAM 11.1.2.3) is configured as Identity Provider in this federation SSO implementation. Active Directory is configured as the user Identity Store.
User has configured the saml response header $user.groups to be returned as part of saml assertion post user authentication. Though the other attributes like email, cn are returned, the group header is returned as NULL instead of returning the set user groups from the Identity Store Active Directory :
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Cause |
Solution |