SAML - users not deleted #925

Open
opened 2026-03-04 11:20:00 -05:00 by deekerman · 2 comments
Owner

Originally created by @Vormillion on GitHub (May 28, 2025).

Hi,

We are using SAML for SSO with Azure AD. We can't use Azure AD integration as it fails if user has more than 100 groups in AD.

Everything works fine with SAML but Cloudbeaver is not contacting Azure to check if existing users in configured Azure groups (CB Teams) are still present in Azure.

As a result, if user accessed CB one time, when he was added in proper AD group, then he will be visible in CB as active user forever, doesn't matter if user was deleted from allowed group or was fully removed from AD.

Originally created by @Vormillion on GitHub (May 28, 2025). Hi, We are using SAML for SSO with Azure AD. We can't use Azure AD integration as it fails if user has more than 100 groups in AD. Everything works fine with SAML but Cloudbeaver is not contacting Azure to check if existing users in configured Azure groups (CB Teams) are still present in Azure. As a result, if user accessed CB one time, when he was added in proper AD group, then he will be visible in CB as active user forever, doesn't matter if user was deleted from allowed group or was fully removed from AD.
Author
Owner

@EvgeniaBzzz commented on GitHub (May 29, 2025):

Hi @Vormillion
Thank you for the report.
We will add unmapping from CB groups when a user is removed from a group by the provider.

Just to be clear. Do you mean removing user from all AD groups?

was fully removed from AD

@EvgeniaBzzz commented on GitHub (May 29, 2025): Hi @Vormillion Thank you for the report. We will add unmapping from CB groups when a user is removed from a group by the provider. Just to be clear. Do you mean removing user from all AD groups? > was fully removed from AD
Author
Owner

@Vormillion commented on GitHub (Jun 2, 2025):

Hi,

So there are two cases when CB should delete user or mark is as disabled.

  1. User is fully deleted from AD.
  2. User is deleted from AD group(s) which is allowed in CB.
@Vormillion commented on GitHub (Jun 2, 2025): Hi, So there are two cases when CB should delete user or mark is as disabled. 1. User is fully deleted from AD. 2. User is deleted from AD group(s) which is allowed in CB.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/cloudbeaver#925
No description provided.