Managing SSO group mappings
SSO group mapping maps your SAML attributes to user groups in runZero. A user group explicitly sets the organizational role, which determines what users can do within each organization. To set up a mapping, you name the SSO attribute and the value to match. When a user’s attribute matches, runZero applies the group settings to that user, so SSO users land in the right runZero groups.
For example, your IT team may need administrator privileges. Create a user group with the administrator role, then create an SSO group mapping from the SAML attribute that identifies your IT team to that group. When someone from the IT team signs in to runZero, they get the appropriate access and permissions automatically, with no pre-provisioning of their account. After evaluating all SSO group mapping rules, runZero grants the user the highest privilege assigned for each organization. Where custom roles are involved, the permissions of every role that applies add together.
Creating SSO group mappings
Before you create an SSO group mapping, set up SSO for your organization and create user groups, because a mapping needs both.
Only runZero superusers can create SSO group mappings.
- Go to Your team > SSO settings > Group mappings > Add group mapping.
- In the SSO attribute field, enter the attribute to check for matching values. Your SSO configuration defines these values.
- For Azure AD SSO, the SSO attribute field must match the claim name from Azure AD.
- In the SSO value field, enter a comma separated list of values the attribute can match. On a match, runZero applies the group permissions.
- Click the Group dropdown and choose the user group to assign on a match. The dropdown lists every user group you have created.
- Save the SSO group mapping. It applies the next time the user signs in to runZero.
Changes do not reach users who are currently signed in until they sign out and back in. To apply the SSO group mappings immediately, you can force users to sign out.
Forcing a user to sign out
Permission changes take effect only after the user signs out and back in to runZero. Forcing users to sign out ends their current session, so their updated permissions apply as soon as they sign back in. Only superusers and admins with access to all organizations can force sign-outs.
Go to the Teams page, select the users you want to sign out, and click the sign-out button.
Viewing SSO group mappings
The Group mappings page lists every SSO group mapping. From there you can create, edit, or delete mappings.
Viewing SSO group mapping assignments
To see which SSO groups a user belongs to, go to the Users page. The Groups column shows the number of user groups and SSO groups for each user, with the SSO group count in parentheses.
Click the gear icon under actions to open the user’s settings. The access summary tab lists all of their organizations and roles.
Deleting a group mapping
- Go to the Group mappings page.
- Select the group you want to delete and click the Delete button. All users provisioned through the mapping revert to their account-level permissions.
Searching for SSO group mappings
On the Group mappings page, you can search the table with these keywords:
| Keyword | Description | Example |
|---|---|---|
id |
User’s ID. | id:123456789 |
sso_attribute |
User’s SSO attribute. | sso_attribute:department |
sso_value |
User SSO attribute value. | sso_value:securityteam |
created_at |
Time or date user group was created. | created_at:>2weeks |
updated_at |
Time or date user group was last updated. | updated_at:>1year |
created_by_email |
Email of user who created the group. | created_by_email:user@example.com |
group_id |
User group ID. | group_id:123456789 |
group_name |
User group’s name. | group_name:group1 |
To find a group ID, go to the group config page and enable the ID column from the Columns menu above the data grid.
The group_id keyword is only available for the Users table; for the groups table, use id.
The group_name keyword is only available for the Users table.