Obtaining the Role Assignments

Configure the identity provider and the service provider so that the role assignments can be added to the attribute and retrieved from the attribute.

  1. To export the roles from the identity provider, log in to Administration Console for the identity provider. (In Figure A-3, this is Site A.)

    1. On the Home page, click Identity Servers > [cluster name] > Edit > SAML 2.0 > [Name of Service Provider] > Attributes.

    2. Select the attribute set you created, then move All Roles so this attribute is sent with authentication.

    3. Click OK.

    4. Update Identity Server of Site A.

  2. To import the roles from the identity provider to the service provider, log in to Administration Console for the service provider. (In Figure Figure A-3, this is Site B.)

    1. On the Home page, click Identity Servers > [cluster name] > Edit > SAML 2.0 > [Name of Identity Provider] > Attributes.

    2. Select the attribute set you created, then move All Roles so this attribute is obtained with authentication.

    3. Click OK.

    4. Update Identity Server of Site B.

    5. Continue with Configuring Policies to Process Received Roles.