{ Community }
  • Academy
  • Docs
  • Developers
  • Resources
    • Community Articles
    • Apigee on GitHub
    • Code Samples
    • Videos & eBooks
    • Accelerator Methodology
  • Support
  • Ask a Question
  • Spaces
    • Product Announcements
    • General
    • Edge/API Management
    • Developer Portal (Drupal-based)
    • Developer Portal (Integrated)
    • API Design
    • APIM on Istio
    • Extensions
    • Business of APIs
    • Academy/Certification
    • Analytics
    • Events
    • Hybrid
    • Integration (AWS, PCF, Etc.)
    • Microgateway
    • Monetization
    • Private Cloud Deployment
    • Insights
    • IoT Apigee Link
    • BaaS/Usergrid
    • BaaS Transition/Migration
    • Apigee-127
    • New Customers
    • Topics
    • Questions
    • Articles
    • Ideas
    • Leaderboard
    • Badges
  • Log in
  • Sign up

Get answers, ideas, and support from the Apigee Community

  • Home /
  • Edge/API Management /
avatar image
0
Question by Laura Llewellyn · Apr 26 at 05:54 PM · 42 Views management apisamlorganizations

SAML, management APIs, and multiple organizations

We will soon have Edge for the Cloud, and we are planning to create 2 organizations, A and B.

We will eventually want to enable SAML on both organizations, but we'd like a few users to be able to experiment with org A while we admins figure out SAML with org B.

Reading the docs, we work with support to create an identity zone, put Org B into that zone, make sure any users for Org B exist in our identity provider, and then enable SAML (nutshell version!). Once we do that, any scripts or management API access must also use SAML; no longer can basic auth be used.

My questions: if we follow this approach, will folks still be able to log into the Edge UI with basic auth and access Org A? What about the management APIs? The management API using SAML docs note:

Prerequisite: You must enable SAML for at least one organization before you can use it to access the management API.

but does not explicitly note if the management APIs can still be accessed with basic auth for organizations that are NOT SAML-enabled.

Comment
Add comment
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Close

2 Answers

  • Sort: 
avatar image
0

Answer by davidmehi · Apr 29 at 04:21 PM

Hello - yes, only if the org is SAML enabled will you need to access the management API with SAML. If it is not SAML-enabled, then you can still access the management API with basic auth. It doesn't matter if the same company owns both orgs.

Comment
Add comment Show 1 · Link
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users
avatar image Laura Llewellyn · Apr 29 at 04:40 PM 0
Link

So effectively, as soon as one org is SAML enabled, then the management API is SAML-enabled also?

What about the org that is not in the SAML-enabled identity zone? Can users still log into that with basic auth?

avatar image
0

Answer by davidmehi · Apr 29 at 04:46 PM

Yes, as soon as it's SAML enabled, then the mgmt api is as well. The users will login with their SSO credentials.

Yes, if the org is not SAML-enabled, then they continue to login with their apigee credentials.

Comment
Add comment · Link
10 |5000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by Apigeeks only
  • Viewable by the original poster
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users

Follow this Question

Answers Answers and Comments

67 People are following this question.

avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image avatar image

Related Questions

What is the expiry of SAML Refresh token , generated as Part of Apigee Edge SAML OAuth2 support? 0 Answers

How to use Edge in combination with SAML tokens 3 Answers

Error with special character in password 4 Answers

Enabling two factor authentication for all users of an organization in the APIGEE Edge Cloud 1 Answer

How to obtain the the Management API ClientID:Secret ? 1 Answer

  • Products
    • Edge - APIs
    • Insights - Big Data
    • Plans
  • Developers
    • Overview
    • Documentation
  • Resources
    • Overview
    • Blog
    • Apigee Institute
    • Academy
    • Documentation
  • Company
    • Overview
    • Press
    • Customers
    • Partners
    • Team
    • Events
    • Careers
    • Contact Us
  • Support
    • Support Overview
    • Documentation
    • Status
    • Edge Support Portal
    • Privacy Policy
    • Terms & Conditions
© 2019 Apigee Corp. All rights reserved. - Apigee Community Terms of Use - Powered by AnswerHub
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Create an article
  • Post an idea
  • Spaces
  • Product Announcements
  • General
  • Edge/API Management
  • Developer Portal (Drupal-based)
  • Developer Portal (Integrated)
  • API Design
  • APIM on Istio
  • Extensions
  • Business of APIs
  • Academy/Certification
  • Analytics
  • Events
  • Hybrid
  • Integration (AWS, PCF, Etc.)
  • Microgateway
  • Monetization
  • Private Cloud Deployment
  • Insights
  • IoT Apigee Link
  • BaaS/Usergrid
  • BaaS Transition/Migration
  • Apigee-127
  • New Customers
  • Explore
  • Topics
  • Questions
  • Articles
  • Ideas
  • Members
  • Badges