<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007B3IzUCAVOkta Classic EngineSingle Sign-OnAnswered2024-04-15T11:21:46.000Z2021-09-10T20:38:02.000Z2021-09-13T21:53:48.000Z

yaaq7 (yaaq7) asked a question.

SAML assertion for multiple group users under one primary account

We are using an application that shares content across 100s of other firms with us via a group account. Is there a way to add to the SAML assertion to pass through those group accounts under the primary user's Okta account?


  • Thank you for your inquiry, Boris!

     

    We currently posses the means to send all Group Memberships through the SAML assertion, or any select Groups that match a search criteria.

     

    When creating your custom SAML app, under Configure SAML or for existing SAML apps go to General > SAML settings > edit and navigate to Configure SAML:

     

    • We can configure our app to pass along the Group Membership of a user under the Group Attribute Statements (optional)
    • Name is going to be the attribute identifier that your app is expecting to receive. For example it's looking for an attribute name "Groups" which contains as values the group memberships of a user
    • Name format can be unspecified
    • Filter by "Matches Regex" and enter this value: (.*)

    Screenshot 2021-09-14 005355 

    Now all your user's Group Memberships in Okta will be passed along in the SAML assertion as such:

    Screenshot 2021-09-14 005028 

    If your scenario does not match what I have described, please feel free to open a support ticket with us so that we may investigate your request.

     

    Thank you,

     

    Andrei Niculae

    Technical Support Engineer

    Okta Global Customer Care

    Expand Post
This question is closed.
Loading
SAML assertion for multiple group users under one primary account