Configuring Roles & Groups in the Application Portal
Introduction
Your organization likely already assigns corporate users to groups according to their job title, department, business unit, and other important attributes. These groups allow an organization to apply access controls and policies to logical sets of users in a consistent manner, instead of managing each user individually.
It is important to note that the actual creation and formation of groups occurs in your IdP. Please refer to the documentation of your IdP on how to form groups. The Application Portal is intended to manage access to Conga applications for the groups created in the IdP. The following links will help direct you to the documentation for group formation in two popular IdPs.
EXAMPLE
Doug, an IT administrator, is tasked with setting up group access to the following Conga products: Control, Opportunity Management, and Guidance. His company uses Entra ID for its IdP. He must follow the protocol for setting up groups in Entra ID. Once he has done that, he can follow the instructions here to manage access for those groups in the Conga products.
This document describes how to control user access to applications within the Conga ecosystem by leveraging the existing groups in your corporate Identity and Access Management (IAM) solution, such as Microsoft Active Directory. When a user logs in, their group memberships are communicated to the Application Portal via the user's selected IAM, such as Microsoft Active Directory Federation Services (ADFS) or other third-party providers.
This topic will cover:
- Roles & Groups User Interface
- Controlling Access to the Application Portal Administration Features
- Assigning Groups to Roles
The information within this document is intended for administrators within information technology, security, or similar technical departments. The instructions require that your organization has already integrated an IAM with the Application Portal, so that users are able to log in to the Application Portal, and that your user account is a member of one or more groups(s) with administrative control of the Application Portal.
Documentation for setup and IAM integration instructions, including the initial designation of an administrative group, can be found in the Application Portal Configuration Guide.
Roles & Groups User Interface
- Log into the Application Portal using your organization’s user credentials.
- Select Environment Management from the Admin menu drop-down. If the Admin menu is not visible, then your user account is not a member of a group that permits the Application Portal administration.
- The Roles & Groups tab under Environment Management provides the following information:
- Available Conga applications and services. The Application Portal always appears first.
- Available built-in Roles for the selected application or service.
- The designated primary Identity Provider (IdP). When multiple IdPs are configured, additional columns will appear for each non-primary provider.
- Groups which have been granted the role. If multiple Identity Providers are configured, groups are assigned separately for each provider.
- Tabs switch between managing built-in App Roles and Custom Roles defined by you (not covered in this Tech Note).
Controlling Access to the Application Portal Administration Features
Each application or service in the Conga ecosystem can have different built-in roles. The Application Portal has two built-in roles controlling access to features and settings within the portal.
- Tenant Admin
This role is intended for “super users” responsible for managing access control and security across your Conga solutions; it should be limited to groups containing only a few, highly-trusted individuals in information technology, security, and similar positions. Tenant Admin role is only available for the primary identity provider. Users assigned to this role can:
- View, assign, and remove groups from any App Role (including the Application Portal itself)
- Create, delete, view, and assign/remove groups from any Custom Role
- Create, edit, and delete Service Accounts
- Grant or revoke access to application and service APIs for Service Accounts
- Modify the maximum session idle timeout
- Enable or disable Conga Support access g. Manage configured Identity Providers
- User API Access
This role is intended for developers and other technical staff working or integrating with Conga APIs. It can be useful when manually using Conga APIs by users who do not have access to Service Account credentials. See User API Access documentation for more information.
- Please discourage users from sharing tokens with unauthorized parties. Anyone possessing a bearer token will be permitted access to the requested API until the token expires.
Assigning Groups to Roles
- Below is the user interface for assigning groups to roles in the Application Portal.
- Click on the list of groups to show a list of all groups found in your environment.
- The list of groups is populated from your IDP(s) during the IDP integration process.
- Check all groups to assign to the respective role and click Save Changes.
- Groups that are not assigned a role will have user-level access to the Application Portal.
Product Specific Roles
Many solutions will have preconfigured roles. For more information on the roles available by product, please use the links below.
Appendix
Populating the list of Groups
- If your IDP is Entra ID or ADFS, all groups in the IDP will be listed in the Groups drop-down.
- If your IDP is Salesforce, the Groups drop-down is populated based on Salesforce Permission sets and Profiles.
- For other SAML 2.0 integrations, the user must be a member of the group from the IDP in order to populate the Groups drop-down.
