Mapping User Groups for Local Authorization

Administrators can map user groups manually for external users login through SSO by using either Manual mapping or Birthright.

Manual Mapping

Once the user logins to AppViewX using SSO if no proper Roles are passed in the Assertion the user will end on a No Usergroup found page. Now the administrator can log in with the default login URL https://ip:port/appviewx/login and navigate to Account > Users. The user who has not logged in will have the user-created tag and will be in an inactive state. Administrators can modify the user and map the user to a user group that is available and this will enable the user to login successfully on the next attempt.

Birthright Role

The administrator can enable a birthright role and map a user group by default for all the SSO users to log in initially when they do not have a role/user group passed in the SAML assertion. This would enable the user to login successfully and access the application with the access given in the specific user group. If required now the administrator can create different sets of user groups and assign manually to the respective users who do not need the birthright user group which will be reflected in the subsequent login.