Moving from one SAML identity provider to another requires a workflow beyond creating and disabling SAML providers in Control Panel. You will need to complete the in-place SAML provider or external-to external SAML provider update process. When users log into Foundry using the new SAML provider, Foundry will provision a new, duplicate user account for them. Groups coming from the new provider will be duplicated as well. Some consequences of not performing a proper provider update include:
To prevent the above issues, users must be migrated from the old SAML provider to the new SAML provider before switching over to using the new provider. There are two options for this:
This is the simplest option and should be taken only if the current and target identity providers share the same attributes. In particular, the value to which the ID attribute maps must not change or users will get an entirely new account provisioned in Foundry.
If the ID attributes of incoming users or groups in the new identity provider are different from existing ID attributes, follow the external-to-external SAML provider update process.
Follow these steps to perform an in-place SAML provider update:
From Control Panel, navigate to the Authentication tab under Enrollment Settings. Find the SAML provider you want to update, then click on the Actions dropdown and select Manage.
In the SAML section, select Manage.
Download the SAML integration metadata XML. Update your SAML application on the identity provider side.
Under Identity provider metadata, upload your new identity provider federation metadata file to Control Panel.
Test that the new integration works as expected and that user attributes do not change and users do not get a new Foundry account provisioned.
Follow these steps to perform an external-to-external SAML provider update:
From Control Panel , navigate to the Authentication tab under Enrollment Settings. Under Authentication providers, select Add provider and add the new provider.
Learn more about configuring SAML 2.0 integration to add a new SAML provider.
Test the new SAML integration using a test account.
Disable the integration temporarily to avoid having duplicate providers enabled at the same time.
Contact your Palantir representative for help migrating users from the old provider to the new provider.