Attribute Mapping for SSO

Map user information related to Single Sign On from the Attribute Mapping page. Provide information such as:
  • Email
  • Group
  • First and Last Name
  • ExtremeCloud IQ role.
Note

Note

The Email and Group attributes are required.

Select common attributes from the Mapped Security Assertion Markup Language (SAML) Attribute drop-down box, or modify any value based on the IDP settings.

ExtremeCloud IQ currently supports a single IDP group and mapping to ExtremeCloud IQ role. Though multiple IDP groups can be listed, only the top assignment is taken into effect. To reorder the list of groups to change the currently active group assignment, drag and drop the entry into the new position in the list.

When a user logs in for the first time using Self Enabled SSO, ExtremeCloud IQ creates the user and role according to the group mapping. For more information about role administration in ExtremeCloud IQ, see Add an Admin Account.

Use this task to map the IDP groups to ExtremeCloud IQ roles.

  1. Select Add a group name mapping.
  2. Enter the IDP group name in the box on the left.
  3. Select the ExtremeCloud IQ role in the box on the right.
  4. Select Save and Finish.