SAP Knowledge Base Article - Preview

3792170 - pingfederate sso: map idp groups to leanix roles without using a leanix standard role group name

Symptom

  • PingFederate has no feature to create role values, the names of the active directory groups get sent as the "role" attribute value
  • Users need LeanIX roles to be assigned via SAML (VIEWER, MEMBER, ADMIN) without changing internal group naming conventions.


Read more...

Environment

  • Product: SAP LeanIX solutions
  • SAP LeanIX MTM Single Sign-on

Product

SAP LeanIX solutions all versions

Keywords

pingfederate, sso, saml, leanix roles, role mapping, authorization attribute, admin, member, viewer, group mapping, idp, attribute transformation, invite only, metadata, production configuration , KBA , LIX-MTM-SSO , SAP LeanIX MTM Single Sign-on , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.