<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00008W2wsrSABOkta Classic EngineSingle Sign-OnAnswered2024-03-25T16:16:13.000Z2020-05-16T20:20:04.000Z2020-05-25T19:31:35.000Z

5rgp4 (5rgp4) asked a question.

Send AD-based group email address in SAML assertion

I understand you can send group names in the SAML assertion using "group attribute statements" in SAML app config. However, I want to send group email addresses associated with AD. Note : I am synching my AD groups into Okta.


  • User15869522308388393993 (Vendor Management)

    Thank you for contacting Okta,

     

    You can send group names in the SAML assertion by using the “SAML 2.0 Template” that has an section for Group name and Group filter.

            When the Group Name option is set, if a user belongs to any groups in Okta, those groups will be included in the SAML Response Attribute statement. Used in conjunction with Group filter. Using the Group filter section you would need to create an expression that will be used to filter groups. If the Okta group name matches the expression, the group name will be included in the SAML response.

             Please note that using the above information is only for Okta Groups, so you you may need to create those groups in Okta, and assign users to those groups respectively.

     

    Have an nice day,

     

    Paul Munteanu

    Technical Support Engineer

     

    Expand Post
This question is closed.
Loading
Send AD-based group email address in SAML assertion