Create IdP group mapping
- Updated: 2024/03/21
Create IdP group mapping
As an administrator, you can create Identity Provider (IdP) group mappings to determine the Control Room roles and licenses to be assigned for automatic user account provisioning.
Prerequisites
- Ensure that the IdP administrator has configured the Control Room
as a single sign-on (SSO) application and updated details such as IdP entity ID,
service provider entity ID, Assertion Consumer Service (ACS) URL, user
attributes, group attributes, and so on, on their IdP portal.
- For more information, see your IdP documentation.
- For examples, see IdP group mapping examples.
- The IdP group attributes must be set to SecurityGroups in the IdP portal so that the Control Room can use this as the key to identify the group information in the SAML assertion.
- Ensure that the IdP administrator has configured the user groups in their IdP whose users need be automatically provisioned in the Control Room.
Procedure
Next steps
- Enable SAML automatic user account provisioning. See Enable SAML automatic user account provisioning.
- Manage IdP group mapping. See Manage IdP group mapping.