SAML groups manage permissions for all SAML users that are members of the group. You
must have at least one enabled SAML configuration to access the SAML Groups page.
For more information about SAML configurations, see Creating a SAML Configuration in Faspex.
SAML groups are created in Faspex one of two ways:
- Automatically create a SAML group in Faspex: When a SAML user with group
membership logs in, Faspex automatically creates a new SAML group for that group
if the SAML group does not yet exist in Faspex. If the SAML user is a member of
multiple groups, Faspex creates a new SAML group for each group.
Note: If an admin
enables the
Restrict access to known groups feature for the SAML
configuration, only members of existing Faspex SAML groups can log in. This also means that
new SAML groups are not automatically created when SAML users log in. For more information
about SAML configuration options, see
Configure SAML Options.
- Manually create a SAML group in Faspex: Once a SAML user that is a part of that
SAML group logs into Faspex, the Faspex SAML group is mapped to the external
SAML group.
The following instructions describe how to manually create a SAML group in Faspex.
These instructions require that Faspex have at least one enabled SAML
configuration.
-
Go to Accounts > SAML Groups and click New
Group.
-
Enter the group name. This is the distinguished name (DN).
-
From the SAML Configuration drop-down menu, select the
SAML configuration this group is associated with.
-
Click Edit Additional Permissions to configure
parameters such account permissions and package deletion parameters. For more
information about additional permissions, see SAML Group Permissions.
-
Click Create.
On the SAML Groups page, you can to activate, deactivate, or remove existing groups
from the
Actions drop-down menu. The Sync option is not available
for SAML groups.
Note: If a user belongs to only one group and that group is deactivated,
the user cannot login anymore. If a user belongs to multiple groups and at least one
of these groups is active, the user can log in.