Assigning the Local Roles Based on Remote Roles and Attributes

You can configure attributes based on the roles you select in the Attribute set field. You can log in to and authenticate based on roles federated in the Origin Identity Provider, Target Service Provider and the Brokering Service Provider configuration.

Origin Identity Provider Role Attribute Configuration

  1. On the Home page, click Identity Servers > IDP Global Settings > Attribute Sets > [Select Attribute] > Mapping Plus icon.

  2. Select the local attribute name from the list.

  3. Specify the remote attribute name for the selected local attribute.

  4. Click Save.

  5. On the Home page, click Applications > [Select a Cluster] > SAML2 IDP Brokering Application > Attributes.

  6. Click edit icon and select the role from Attribute Set.

  7. Click Done > Save.

Allowed Service Provider Role Attribute Configuration

  1. On the Home page, click Identity Servers > IDP Global Settings > Attribute Sets > [Select Attribute] > Mapping Plus icon.

  2. Select the local attribute name from the list.

  3. Specify the remote attribute name for the selected local attribute.

  4. Click Save.

  5. On the Home page, click Applications > [Select a Cluster]> [application name] > SAML2 SP Brokering Application > Attributes

  6. Click edit icon and select the role from Attribute Set.

  7. Click Done > Save.

Brokering Service Provider Role Attribute Configuration

Roles set, attribute configured in origin identity provider, and target service provider are added and mapped in the brokering service provider attribute configuration.

  1. On the Home page, click Identity Servers > IDP Global Settings > Attribute Sets > [Select Attribute] > Mapping Plus icon.

  2. Select the local attribute name from the list.

  3. Specify the remote attribute name for the selected local attribute.

  4. Click Save.

  5. On the Home page, click Applications > [Select a Cluster]> [application name] > Brokering > SAML 2.0 > SAML2 SP Brokering Application > Attributes.

  6. Click edit icon and select the role from Attribute Set.

  7. Click Done > Save.