How to Filter Groups with Regex in Okta
Last Updated:
Overview
Okta administrators can use Regex filters in a Secure Assertion Markup Language (SAML) application to send specific groups to an application. This configuration is useful when an application requires a group attribute statement where the filter must limit the results to a set of groups that use a particular prefix.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Secure Assertion Markup Language (SAML) Application
- Group Attribute Statement
Solution
How do administrators send specific groups to an application using a regex filter?
- Access the Okta Admin Console.
- Select the application that needs the group attribute statement.
- Click on the Sign On tab, and scroll down to the "Attributes Statements" section
- Expand the "Show legacy configuration" section and scroll down to the Group Attribute Statements section.
- Enter a name for the group attribute statement.
- In the Matches Regex field, enter the regex filter that matches the groups intended for the application.
- Save the changes to the group attribute statement and assign it to the application.
For example, to send groups A, B, C, and D, use the following regex filter:
.*groupA.*|.*groupB.*|.*groupC.*|.*groupD.*
Apply a wildcard regex filter to send all groups assigned to a user.
.*
When using regex filters in Okta, the dot character (.) matches any character, and the pipe character (|) separates multiple regex patterns. The regex pattern must match the group names exactly as they appear in Okta.
Alternatively, when there is no need to send specific groups, the following expression can be used to send multiple groups with the same attribute that start with either “Group” or “Other_Group” (replace these values with the intended group names):
(Group+(.))|(Other_Group+(.)))
NOTE: The Regex needs to be Matches, not StartsWith. The resulting values will behave as a StartsWith condition.
The group filter processes the wildcard regular expression differently based on the configuration.
Review the following behaviors and configurations to understand how the Group Filter processes the wildcard regular expression in SAML integrations.
-
When the regular expression
.*is entered in the Group Filter of a Group Attribute Statement, the assertion includes all groups assigned to the user. -
This selection comprises both native Okta groups and imported Active Directory groups.
-
If only Active Directory groups are required, enter a regular expression that matches a specific naming convention, for example,
AD_.*.- Or use
^(?!groupName$).*- This means "Match everything except the exact string groupName." This will instantly strip that group from the assertion for all users. Replace the groupName with the group that should be excluded.
- Or use
