The Attribute Mapping page is where you map user information such as Email, Group, First Name, Last Name and ExtremeCloud IQ role.
The Email and Group attributes are required. The mapped Security Assertion Markup Language (SAML) attribute drop-down box gives options to select from common attributes, or you can change to any value based on the IDP settings.
ExtremeCloud IQ currently supports a single IDP group and mapping to ExtremeCloud IQ role. Though multiple IDP groups can be listed, only the top assignment is taken into effect. To reorder the list of groups to change the currently active group assignment, drag and drop the entry into the new position in the list.
When a user logs in for the first time using self enabled SSO, ExtremeCloud IQ creates the user and role according to the group mapping. For more information about role administration in ExtremeCloud IQ, see Add an Admin Account.
To map the IDP groups to ExtremeCloud IQ roles: