Step 5 — Map ExtremeCloud IQ User Profile Attributes to SAML Attributes for Entra ID

In ExtremeCloud‌ IQ, from the Attribute Mapping tab, you must map the appropriate User Profile Attributes to the SAML Attributes sent from the IdP. These strings must be created and in sync with both IdP and SP. The following SAML Attributes are required for Entra ID Single Sign-On:
  • First Name
  • Last Name
  • Email
  • Group
Note

Note

To generate the SP Metadata required to complete the IdP SAML configuration, the SAML strings cannot be configured on the IdP until the ExtremeCloud‌ IQ workflow is completed. You must complete the ExtremeCloud‌ IQ workflow first. If you do not know the SAML Attribute Strings, add place holder data to save and complete the configuration.

The following table includes the required strings for integration with Entra ID.

Table 1. ExtremeCloud ID - Required Strings for Microsoft Entra
User Profile Attribute SAML Attribute
First Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
Last Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
Email http://schemas.xmlsoap.org/ws/2005/05/identity/claims/email
Group http://schemas.microsoft.com/ws/2008/06/identity/claims/groups