You are configuring Administrator SSO using SAML 2.0 with roles based on group membership. In this scenario, how is the administrator group passed from the IdP within the SAML assertion to Netskope?
When configuring SAML 2.0 SSO for Netskope administrator access with group-based role assignment, the administrator’s group membership must be communicated from the Identity Provider to Netskope within the SAML assertion. Netskope expects the group attribute to be passed using the attribute name “GROUP_NAME” in the SAML response. This attribute maps the IdP group membership to the corresponding admin role configured within the Netskope tenant. If the attribute name does not match exactly, for example if “ADMIN-GROUP” or “OU-GROUP” is used instead, Netskope will not be able to resolve the group assignment and the administrator will either receive no role or default-level permissions. This attribute name convention is explicitly documented in Netskope’s SAML SSO configuration guide for administrator access management.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit