What Is Automatic Assignment for SAML Apps?
You can link the identity provisioning settings for each service with an already-created SAML app.
By linking identity provisioning settings to a SAML app,
members assigned to the identity provisioning settings can also be automatically assigned to the SAML app.
This lets you centralize member assignment tasks, reducing the administrative burden.
- Each identity provisioning setting can be linked to one SAML app.
- Each SAML app can be linked to multiple identity provisioning settings.
Note: Once this setting is configured, members and groups can no longer be assigned manually on the SAML app side.
Setup Steps
Prerequisites
Create and complete the configuration of the SAML app to be linked in advance, and confirm that SSO is working correctly.
For instructions on configuring SAML apps by service, see here
Linking with Identity Provisioning Settings
- Log in to the Admin Page and select the previously created SAML app from "App".
- Click the "Edit SAML App Settings" button.
- On the SAML app settings screen, check the "Identity Provisioning Member Assignment" checkbox and click "Save".
Note: You cannot check this box if members or groups are already assigned to the target SAML app.
Remove the assigned members/groups first, then check the box.
Note: Once you complete this step, members and groups can no longer be assigned manually on the SAML app side.
- From "Settings > Optional Features > Identity Provisioning", select the identity provisioning setting you want to link the SAML app to.
- Click the "Edit" button next to the icon to open the edit screen.
Turn on the toggle for "SAML Settings > SAML App" and click "+ Select SAML App".
- The SAML app selection screen opens, showing the SAML apps for which "Identity Provisioning Member Assignment" has been configured.
Select the app you want to link.
-
Confirm that the selected app is displayed, then click "Save".
Confirm that the app appears on the My Page of the target members.
Once the configuration is complete,
you can navigate from the ① SAML App name link on the SAML app settings screen to the identity provisioning screen, and from the ② Service name button on the identity provisioning screen back to the SAML app screen.