System administrators User management Setting up roles and permissions based on SSO

Setting up roles and permissions based on SSO

Published on: May 28, 2024
Edited on: November 28, 2024

In eformity, you can create different roles to assign specific permissions to users. Manually assigning these roles can be time-consuming. Therefore, eformity offers the capability to automatically assign defined roles based on the Single Sign-On (SSO) provider. This article explains how to set this up.

Requirements

Before you start configuring roles and permissions based on SSO, ensure the following requirements are met:

Step 1: Log in to eformity.net

Most tasks related to setting up roles and permissions are done through the eformity web environment. Log in with your personal credentials at yourcompanyname.eformity.net.

Step 2: Navigate to 'System Management'

Once logged in, navigate to the 'System Management' section. Click the hamburger menu icon. This icon is circled in the image below.

A new element will appear on the left side of the page, displaying up to five different tiles. Click the tile titled 'System Management' to access the system administration section.

Step 3: Go to 'Identity providers'

On the new page, there will be a menu on the left. Click 'Identity Providers' (1 in the image). Then, select one of the available identity providers (2 in the image).

Step 4: Edit role

A new window will open on the right side of the page. Click the blue 'Edit' button in the 'Roles' section. This is visually represented in the image below.

After clicking 'Edit', another window will open. In this new window, select the desired role you want to configure with SSO. Click 'Edit'.

Danger icon

Note!

When assigning roles based on an identity provider, these roles cannot be used for manually adding users to these roles.

Once you have clicked 'Edit', another new element will appear on the right side of the page. Enter the name (or claim) of the group as used by the identity provider. Finally, click 'Save'.

Info icon

Tip!

You do not have to link all roles through the identity provider. You can also manually assign roles outside of the identity provider.

Warning icon

Note!

Roles are not actively synchronized. Roles are only (re)assigned when the user logs in.