Skip to main content
Skip table of contents

SSO Mappings

This feature enables customers to automatically assign roles and organizational associations based on attributes in Single Sign-On (SSO).

image-20250321-151710.png

This will only work for testing or configuration if you have set up SSO with your instance.

Overview

This guide explains how SAML authentication works in the system, with particular focus on role assignments and user management.

Role Assignment Behavior

Initial User Creation

  • When a user first authenticates through SAML, the system assigns roles based on the SAML configuration

  • Role assignments are determined by the mapping rules in your SAML configuration

  • Default mappings are applied when no specific mapping rules match

Important Notes About Role Updates

  • Role assignments occur only during initial user creation

  • The system does not automatically update roles on subsequent logins

  • Changes to group membership in the identity provider are not automatically reflected

Updating User Roles

Current Behavior

To apply new role assignments from SAML configuration:

  1. Delete the existing user account

  2. Have the user log in again through corporate login

  3. New roles will be assigned based on current SAML configuration

Limitations

  • Manual user modifications will be preserved until the user is deleted

  • There is no automatic synchronization between identity provider groups and system roles

  • Changes to SAML role mappings will only affect new users or deleted/recreated users

Best Practices

  • Plan role assignments carefully before initial user creation

  • Document any manual role modifications

  • Consider the impact of deleting users before performing role updates

  • Communicate to users when they need to re-authenticate after role changes

Future Considerations

The following improvements are being considered:

  • Optional automatic role synchronization

  • Configurable behavior for role updates (preserve vs. override)

  • Integration with identity provider group changes

Notes for Administrators

  • Only one default mapping can be configured in the system

  • Default mappings are applied when no other mapping rules match

  • Consider the trade-off between automatic updates and preserving manual modifications

For additional support or questions about SAML configuration, please contact helpcenter@thruinc.com

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.