Configure a shared attribute for transferring the roles.
In Administration Console of the Site A (the identity provider), click Devices > Identity Servers > Shared Settings.
Click Attribute Sets, then New.
Specify a Set Name, such as role_sharing, then click Next.
Click New and specify the following details:
Local attribute: Select All Roles.
Remote attribute: Specify a name, such as roles. Ensure that you use the same remote name in the mapping for both the identity provider and the service provider.
Leave the other options set to their default values.
Click OK, then click Finish.
Your newly created attribute mapping appears in the list of Attribute Sets.
Repeat Step 1 through Step 5 on Site B (the service provider).
Continue with Obtaining the Role Assignments.