Configuring groups and roles for external users - User Guide - BlueCat Horizon

BlueCat Horizon User Guide

ft:locale
en-US
Product name
BlueCat Horizon

Access permissions for external users comes from group claims sent by your identity provider. To give external users access to data and functions in BlueCat Horizon, you need to assign them to groups with the appropriate roles and permissions when configuring the SSO connection with your external identity provider. First, however, you need to create those groups and roles in BlueCat Horizon, so you can reference them in your external configuration.

To create SSO groups:

  1. Navigate to User management > Groups and select New to create the group(s) for your external users. Create as many groups as you need for the different users you will add, based on the way you want to separate and assign roles and access permissions.
    Note: These groups should have the same values as groups that your identity provider will return in the groups claim.
  2. Create roles that you will assign to these groups. For instructions on creating roles, refer to Creating roles.

When configuring the SSO connection with your identity provider, add these groups when you assign users and configure groups mappings.

Group matches between the identity provider and platform are checked every time the user uses SSO to log in. If there is no match between the groups in BlueCat Horizon and the groups you add to the SSO configuration with your identity provider, the external users will not be assigned to any groups and, therefore, have no access permissions.