This article provides an overview of user synchronization capabilities in ProjectWise 2023.
User synchronization is being continuously improved. This page will be used to post updates improvements to user synchronization capabilities. Subscribe to this page for updates.
ProjectWise datasource User synchronization is used to control user access to ProjectWise based on their membership in organization or project user groups that are defined and managed outside of ProjectWise environments.
In ProjectWise versions before 2023 ProjectWise User Synchronization Service was used for this purpose. It could synchronize users and groups from one or more domains in Active Directory. User Synchronization Service is no longer available in the latest releases of ProjectWise.
Starting with ProjectWise 2023 Bentley IMS became the primary location for defining users and their entitlements for use with Bentley applications. Currently most Bentley applications and all cloud services require IMS authentication. ProjectWise user management is also evolving to adjust to this change.
Automatic user provisioning from Microsoft Entra ID to Bentley IMS must be configured first. This ensures that all required users and groups are readily available for synchronizing with ProjectWise datasources.
Detailed configuration instructions can be found here: https://bentleysystems.service-now.com/community?id=kb_article&sysparm_article=KB0113212
Limitations:
ProjectWise 2023 (and later) introduces several new settings that control user synchronization.
Datasource properties:
User group property:
User membership in IMS groups is checked and updated during each login for users that match Dynamic Creation identity filer criteria.
Dynamic creation enables user accounts to be created at the time of login when they meet identity filtering criteria. If group assignment is configured, users will also be assigned to ProjectWise groups, based on their IMS group membership.
Important security consideration:
Limitations:
User Synchronization Profiles (Active User Synchronization)
ProjectWise 2023 and later is capable of actively synchronizing all IMS users and their group membership. Currently the cloud service required for this feature to work is not publicly available, so it is not yet possible to setup the synchronization using this method.
Notice that Dynamic user creation, combined with user group updates on every login already provides substantial dynamism in ensuring that users can only access what they should without requiring all users to be preloaded into datasource.
Current synchronization capabilities are different compared to legacy User Synchronization Service. If you are considering upgrading to the latest generation of ProjectWise and you think that current capabilities do not meet your needs, create a service case for a deep dive into your use case. There may be alternative solutions avalable.