Ad Widget

Collapse

SSO/SAML-provisioned users and setting Media severity types

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • vacri
    Junior Member
    • Nov 2023
    • 5

    #1

    SSO/SAML-provisioned users and setting Media severity types

    Hi folks,

    We've got a greenfields Zabbix 6.4 setup and have enabled SSO-provisioned users via SAML, which locks us out of individually-managed users' Media types. We've enabled SAML JIT but not SCIM.

    Media types are configured in the SAML configuration console, and we've only added email to the list. There are only three fields available when adding email: Name/Media Type/Attribute, none of which related to severity levels.

    The problem is that this adds a media type to users which respond to ALL severity levels. If we reboot a server, we get 15 or so Info emails saying 'service restarted' and 10 minutes later the same number of 'resolved' emails.


    How do we set the notification severity levels for SAML/SSO users? The Media Types documentation assumes that you're not using SAML (which blocks you from using per-user settings), and the SAML documentation doesn't mention Media Types' severity (and there's no option in the config box)


    Have attached screenshots of the problem config areas


    Thanks
    Attached Files
    Last edited by vacri; 14-11-2023, 03:30.
  • vacri
    Junior Member
    • Nov 2023
    • 5

    #2
    Turns out that JIT is broken as it does not allow any form of media type variation (times, levels, etc): https://support.zabbix.com/browse/ZBXNEXT-8147

    Solution is to turn off JIT and pre-provision SAML users

    Comment

    • gcalenko
      Zabbix developer
      • Mar 2017
      • 27

      #3
      JIT allow to provision only user permissions and a few user personal information fields. Improvements for user media provisioning will be done in https://support.zabbix.com/browse/ZBXNEXT-8760

      Comment

      Working...