<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assertion attribute Role mappings for SAML in HPE Morpheus Enterprise</title>
    <link>https://community.hpe.com/t5/hpe-morpheus-enterprise/assertion-attribute-role-mappings-for-saml/m-p/7247790#M964</link>
    <description>&lt;P&gt;I just fixed using this solution. Role Mapping is working now.&lt;/P&gt;
&lt;ASIDE class="quote quote-modified" data-post="1" data-topic="1895"&gt;
  &lt;DIV class="title"&gt;
    &lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
    &lt;IMG alt="" width="24" height="24" src="https://avatars.discourse-cdn.com/v4/letter/w/48db29/48.png" class="avatar" /&gt;
    &lt;A href="https://discuss.morpheusdata.com/t/keycloak-saml-sso-role-mapping/1895"&gt;Keycloak SAML SSO - Role Mapping&lt;/A&gt; &lt;A class="badge-category__wrapper " href="https://community.hpe.com/c/administration/14"&gt;&lt;SPAN data-category-id="14" style="--category-badge-color: #c3e3f3; --category-badge-text-color: #FFFFFF;" data-drop-close="true" class="badge-category " title="The Administration category is focused on the administrative settings and concepts within the Morpheus platform.  This includes groups, users, roles, tenants, policies, plans &amp;amp; pricing, reporting, and others."&gt;&lt;SPAN class="badge-category__name"&gt;Administration&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;
  &lt;/DIV&gt;
  &lt;BLOCKQUOTE&gt;
    When using Keycloak as an identity source via SAML, a role mapper must be defined on the Keycloak client configured for Morpheus to map Keycloak roles to Morpheus roles. 
Keycloak 
 &lt;A class="lightbox" href="https://us1.discourse-cdn.com/flex020/uploads/morpheusdata1/original/2X/b/b78d74362a42cfffe327d3001e814114890a35f8.png" data-download-href="/uploads/short-url/qbMrknxccoE7eVYX0LF6c7Vm3Vu.png?dl=1" title="1" rel="noopener nofollow ugc"&gt;[1]&lt;/A&gt; 
The ‘Role attribute name’ that is set on the mapper will need to be defined in Morpheus identity source settings and ‘Single Role Attribute’ needs to be ‘On’. 
 &lt;A class="lightbox" href="https://us1.discourse-cdn.com/flex020/uploads/morpheusdata1/original/2X/0/0ff645d95c35b04c69a2ca69a7a024f919a97af3.png" data-download-href="/uploads/short-url/2hcNy7IJlD9FfQUptbReKuM2Q5Z.png?dl=1" title="2" rel="noopener nofollow ugc"&gt;[2]&lt;/A&gt;
  &lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;</description>
    <pubDate>Sun, 26 Jan 2025 06:55:41 GMT</pubDate>
    <dc:creator>Niranpsk</dc:creator>
    <dc:date>2025-01-26T06:55:41Z</dc:date>
    <item>
      <title>Assertion attribute Role mappings for SAML</title>
      <link>https://community.hpe.com/t5/hpe-morpheus-enterprise/assertion-attribute-role-mappings-for-saml/m-p/7247789#M963</link>
      <description>&lt;P&gt;I have SAML SSO as external identity sources working fine and looking for Assertion attribute for role mapping. SAML from identity source is passing values but i cant find the mapping name on the doc.&lt;/P&gt;
&lt;P&gt;From identity source;&lt;BR /&gt;
…&lt;BR /&gt;
&amp;lt;saml:Attribute NameFormat=“urn:oasis:names:tc:SAML:2.0:attrname-format:basic” Name=“ROLE ATTRIBUTE NAME”&amp;gt;&lt;BR /&gt;
&amp;lt;saml:AttributeValue xmlns:xsi=“&lt;A href="http://www.w3.org/2001/XMLSchema-instance" rel="noopener nofollow ugc"&gt;http://www.w3.org/2001/XMLSchema-instance&lt;/A&gt;” xsi:type=“xs:string”&amp;gt;Admins&amp;lt;/saml:AttributeValue&amp;gt;&lt;BR /&gt;
&amp;lt;saml:AttributeValue xmlns:xsi=“&lt;A href="http://www.w3.org/2001/XMLSchema-instance" rel="noopener nofollow ugc"&gt;http://www.w3.org/2001/XMLSchema-instance&lt;/A&gt;” xsi:type=“xs:string”&amp;gt;CMP Users&amp;lt;/saml:AttributeValue&amp;gt;&lt;BR /&gt;
&amp;lt;/saml:Attribute&amp;gt;&lt;BR /&gt;
&amp;lt;saml:Attribute NameFormat=“urn:oasis:names:tc:SAML:2.0:attrname-format:basic” Name=“lastName”&amp;gt;&lt;BR /&gt;
…&lt;/P&gt;
&lt;P&gt;Morpheus SAML;&lt;BR /&gt;
&lt;/P&gt;&lt;DIV class="lightbox-wrapper"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.hpe.com/t5/image/serverpage/image-id/150239iF8E5DF32F917BA6C/image-size/large?v=v2&amp;amp;px=2000" role="button" title="e087d03ad677bceaed208bca199323f1ec6118e3.png" alt="e087d03ad677bceaed208bca199323f1ec6118e3.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;is there any guide / document to configure role mapping?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jan 2025 23:24:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-morpheus-enterprise/assertion-attribute-role-mappings-for-saml/m-p/7247789#M963</guid>
      <dc:creator>Niranpsk</dc:creator>
      <dc:date>2025-01-25T23:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Assertion attribute Role mappings for SAML</title>
      <link>https://community.hpe.com/t5/hpe-morpheus-enterprise/assertion-attribute-role-mappings-for-saml/m-p/7247790#M964</link>
      <description>&lt;P&gt;I just fixed using this solution. Role Mapping is working now.&lt;/P&gt;
&lt;ASIDE class="quote quote-modified" data-post="1" data-topic="1895"&gt;
  &lt;DIV class="title"&gt;
    &lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
    &lt;IMG alt="" width="24" height="24" src="https://avatars.discourse-cdn.com/v4/letter/w/48db29/48.png" class="avatar" /&gt;
    &lt;A href="https://discuss.morpheusdata.com/t/keycloak-saml-sso-role-mapping/1895"&gt;Keycloak SAML SSO - Role Mapping&lt;/A&gt; &lt;A class="badge-category__wrapper " href="https://community.hpe.com/c/administration/14"&gt;&lt;SPAN data-category-id="14" style="--category-badge-color: #c3e3f3; --category-badge-text-color: #FFFFFF;" data-drop-close="true" class="badge-category " title="The Administration category is focused on the administrative settings and concepts within the Morpheus platform.  This includes groups, users, roles, tenants, policies, plans &amp;amp; pricing, reporting, and others."&gt;&lt;SPAN class="badge-category__name"&gt;Administration&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;
  &lt;/DIV&gt;
  &lt;BLOCKQUOTE&gt;
    When using Keycloak as an identity source via SAML, a role mapper must be defined on the Keycloak client configured for Morpheus to map Keycloak roles to Morpheus roles. 
Keycloak 
 &lt;A class="lightbox" href="https://us1.discourse-cdn.com/flex020/uploads/morpheusdata1/original/2X/b/b78d74362a42cfffe327d3001e814114890a35f8.png" data-download-href="/uploads/short-url/qbMrknxccoE7eVYX0LF6c7Vm3Vu.png?dl=1" title="1" rel="noopener nofollow ugc"&gt;[1]&lt;/A&gt; 
The ‘Role attribute name’ that is set on the mapper will need to be defined in Morpheus identity source settings and ‘Single Role Attribute’ needs to be ‘On’. 
 &lt;A class="lightbox" href="https://us1.discourse-cdn.com/flex020/uploads/morpheusdata1/original/2X/0/0ff645d95c35b04c69a2ca69a7a024f919a97af3.png" data-download-href="/uploads/short-url/2hcNy7IJlD9FfQUptbReKuM2Q5Z.png?dl=1" title="2" rel="noopener nofollow ugc"&gt;[2]&lt;/A&gt;
  &lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;</description>
      <pubDate>Sun, 26 Jan 2025 06:55:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-morpheus-enterprise/assertion-attribute-role-mappings-for-saml/m-p/7247790#M964</guid>
      <dc:creator>Niranpsk</dc:creator>
      <dc:date>2025-01-26T06:55:41Z</dc:date>
    </item>
  </channel>
</rss>

