Once SAML/SSO has been configured, users will be provisioned at login. By default, users will be assigned the Remote Edit User
role. If the SAML IDP is sending group information to Lens, then the Lens Portal can automatically assign a role to a user based on their SAML groups.
How roles are evaluated
A users role is evaluated based on the following criteria:
-
If a users role has a role other than
Deny access
, they use the users assigned role -
If a users role is
Deny access
but they are part of a group that does allow access, then they will be assigned the group’s role -
If a user's role is
Deny access
and they are not part of a group, then they will be denied access
Assigning a role based on SAML groups
-
Login to the Lens Portal. The user must have the 'Access to Settings' permission for the location where the scheduler will be enabled.
-
In the left sidebar, open the
Configuration
menu, then select theSettings
option -
Under the
Roles
group, select theIdentity Mapping
option -
Click the
Add
button -
A
Add role mapping
modal will appear. In theGroup Name
field enter the name of the SAML group. This is case-sensitive. -
In the
Role
field, select the role you would like users that have the specified group name to have. -
Click the
Add
button
Assigning a role to a SAML user
-
Login to the Lens Portal. The user must have the 'Access to Settings' permission for the location where the scheduler will be enabled.
-
In the left sidebar, open the
Configuration
menu, then select theSettings
option -
Under the
Roles
group, select theIdentity Mapping
option -
Check the checkbox next to the user you want to assign a role to
-
Click the
Edit
button -
In the
Role
field, select the new role -
Click the
Edit
button
