<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008WWlLcCALOkta Classic EngineSingle Sign-OnAnswered2022-12-15T16:11:31.000Z2022-12-14T10:12:05.000Z2022-12-15T16:11:31.000Z
Passing group attributes in SAML assertion?

I have a SP-initiated SSO Application using SAML and that is working. I got the idea of the Attribute Statements and Group Attribute Statements in the SAML settings. To take it another step further, I have added some attributes and values under the Groups themselves. Is there any way to pass these attributes/values under a group (which this user is assigned to) as well in the SAML assertion?


  • DonF.81354 (Customer)

    Great question! This is definitely a great use case, one that I have used myself. I would recommend you give the following article a try and let me know if that helps to answer your question.

     

    How to pass a user's group membership in a SAML Assertion from Okta?

     

    This article does a great job of breaking this down easily. I would also recommend you download and install the browser extension SAML-Tracer so you can easily validate that those group attributes are being sent over.

     

    Hope that helps! Thanks!

    Expand Post
    Selected as Best
  • DonF.81354 (Customer)

    Great question! This is definitely a great use case, one that I have used myself. I would recommend you give the following article a try and let me know if that helps to answer your question.

     

    How to pass a user's group membership in a SAML Assertion from Okta?

     

    This article does a great job of breaking this down easily. I would also recommend you download and install the browser extension SAML-Tracer so you can easily validate that those group attributes are being sent over.

     

    Hope that helps! Thanks!

    Expand Post
    Selected as Best
This question is closed.
Loading
Passing group attributes in SAML assertion?