Advent of Code is back! Unwrap daily challenges to sharpen your Alteryx skills and earn badges along the way! Learn more now.
Free Trial

Alteryx Server Ideas

Share your Server product ideas - we're listening!
Submitting an Idea?

Be sure to review our Idea Submission Guidelines for more information!

Submission Guidelines

AD authorization with Authentication via SAML (SSO) with Gallery

At some point we would like Alteryx Gallery to support SSO via SAML and Authorization via AD groups. The way I want is to have Authentication via SAML and Authorization via AD groups. For instance one of our apps Tableau: It does authentication via SAML (SSO) and for authorization, we import AD groups into Tableau thrice a day(stores the groups in a .xml file), once the groups are in the Tableau, we secure the objects within Tableau using that LDAP groups (which kind of become local groups after import). Basically the userid after the successful authentication step is used by the app for authorization.

I just stated Tableau as one of the ways to implement Authentication and Authorization for an enterprise app. If Alteryx Gallery needs to be an enterprise app, you will need to look into this idea. 

 

Thanks
Raj

3 Comments
KylieF
Alteryx Community Team
Alteryx Community Team

Thank you for your feedback and idea!

 

Please be sure to check out our Submission Guidelines as well as other users ideas to likes and comment on. Likes and feedback through the comments really help us better understand what our users need and are looking for in our products.

aplima
7 - Meteor

Exactly the same setup here with Tableau (and many others) and I fully agree with @rajeshr.

If Alteryx wants Alteryx Server to be called an Enterprise ready product and make through thousand of users within an enterprise, Alteryx Server must support SAML (and OIDC) for Authentication along with AD groups for Authorization.

Basically, that's the strategy of many large companies for hybrid cloud setups. Example: Federate AD with Azure AD for authentication, authenticate users via Azure IDP (preferably via OIDC) and use heritage AD groups for authorization on the apps. 

 

DataMeister
7 - Meteor

Until there's a sleek replacement for Microsoft's clunky Active Directory world, let's at least automate as suggested above.