Skip to main content
This article requires you to have at least PADS4 version 2025.2.
After you create your identity provider, manage its role mappings. When a user logs in, PADS4 assigns them PADS4 roles based on the identity provider group to PADS4 role mappings that you configure.

1. Configure mappings

To configure these mappings:
  • On your newly created identity provider, click Identity mappings.
Role Mapping1
  • On the Role mappings tab, click New to create a new role mapping.
Role Mapping2
  • On the role mapping form, fill in two fields:
    • The SSO provider group. This relates to the user group claim that you configured on the external identity provider.
    • The PADS4 roles. These determine the roles assigned to a user based on the external identity provider group they belong to.
Role Mapping3
  • Select an SSO provider group for your role mapping.
    • If the SSO provider group you expect doesn’t exist yet, click New SSO Group to add another group to the list.
Role Mapping4
  • The SSO Group Name only helps you remember the identity of the group you created.
  • The SSO Group id must match the group claim value that you set up in the external identity provider claims configuration.
    • By default, the group claim value is:
      • The user group id for Azure
      • The user group name for Okta
After you fill in the SSO group, click Create to save the group. Then select the group on your role mapping creation form. Role Mapping5
  • Select roles in PADS4.
Select the roles that PADS4 assigns to the user if the user is a member of the selected SSO group. If a role is missing, click New role to create a new role, and then select it. Role Mapping6
  • Click Create to save the role mapping.
  • Repeat this process for each external identity user group that you want to allow access to the application.
If a user from your external identity provider belongs to a group that isn’t in the role mapping table, that user has no rights on the application by default.

2. Update identity provider claims (optional)

You might want to edit the claims mapping on the PADS4 identity provider you created. Do this if you created your identity provider from a custom SAML 2.0 external identity provider, or if you want to extend or update your claims attributes. To update those claims:
  • On your newly created identity provider, click Identity mappings.
Role Mapping7
  • Switch to the Claims tab.
If you created your identity provider from Azure or Okta, this tab might already contain default claims mappings that you can modify if required.
Role Mapping8
  • Create a new claim or update an existing one. If you create a new claim, fill in the following information:
    • The claim name. This relates to the claim name that PADS4 retrieves from the SAML response.
    • The local attribute. This determines the property that PADS4 fills in with the claim value when it creates the PADS4 user.
Role Mapping9
  • You can only choose the local attribute from the list of PADS4 user properties below.