Map Attributes & Create/Manage Groups using SSO
Create & manage user groups
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon >> More >> Map Attributes
| What are Map Attributes & Create/Manage Groups Using SSO? |
|---|
| Map Attributes & Create/Manage Groups Using SSO refers to two methods for creating and managing IdeaScale member groups automatically through Single Sign-On (SSO): mapping a group attribute directly from an Identity Provider (IdP), or mapping other IdP-supplied attributes to profile questions used as criteria for manually created groups. |
Using IdeaScale's Single Sign-On (SSO), Attributes can be mapped and member Groups created or managed in one of two ways: through SSO Group Attribute Mapping, in which groups are created and assigned automatically from an IdP-supplied group attribute, or through SSO Profile Field Mapping, in which other IdP attributes are mapped to profile questions used as criteria for manually created groups.
Role Permissions
- Workspace Administrator: Accesses Map Attributes from the Single Signon Settings page to configure SSO Group Attribute Mapping and SSO Profile Field Mapping, creates Workspace Member Profile Questions used as group-assignment criteria, and overrides or modifies group membership for an IdP-mapped group from Member Management >> Groups. Cannot switch the Auto Assign by SSO setting on or off for an IdP-mapped group (see Exceptions below).
- Member: Logs in through SSO and is automatically assigned to one or more groups based on either the mapped IdP group attribute or the profile question response supplied, depending on the mapping method configured.
TABLE OF CONTENTS
SSO Group Attribute MappingSSO Profile Field Mapping
Exceptions
Frequently Asked Questions
SSO Group Attribute Mapping
If the Identity Provider (IdP) sends a group attribute in the SAML assertion, IdeaScale can automatically create and assign groups with no manual setup required in Member Management >> Groups.
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon
To configure SSO Group Attribute Mapping:
- Select the More option (three dots) beside the SSO name, then select Map Attributes from the dropdown.

- Enter the group name in the attribute field to be used within the Workspace or community via the IdP. The group name is extracted from the SSO assertion based on the Name or Friendly Name provided. If multiple values are entered, the system searches for each one and creates a group as necessary. When a member logs in using SSO, that member is either automatically assigned to the designated group or a new group is created if needed.

Example SAML Attribute:
<saml:Attribute Name="group"> <saml:AttributeValue>Finance</saml:AttributeValue> <saml:AttributeValue>HR</saml:AttributeValue> </saml:Attribute>
With Finance and HR entered as the attributes in the Groups field, a member is automatically placed into both the Finance and HR groups.
A Workspace Administrator can override or modify the membership of an IdP-mapped group from Member Management >> Groups.

Note: The Auto Assign by SSO setting under Group Settings for an IdP-mapped group cannot be switched on or off manually by a Workspace Administrator (see Exceptions below).
SSO Profile Field Mapping
If the IdP sends other attributes — such as department, region, or role — those attributes can be mapped to IdeaScale profile fields and used as criteria for manually created groups. Configuring this method has three parts: creating the profile questions, mapping IdP attributes to those profile questions, and configuring the resulting groups for auto-assignment.
Creating Profile Questions
Profile questions can be created at either the Workspace or community level, depending on where the mapped groups should apply:
- Workspace Member Profile Questions — Path: Workspace Homepage >> Navigation Panel >> Settings >> Workspace Configuration >> Profile Questions.
- Community Member Profile Questions — Path: Workspace Homepage >> Navigation Panel >> Settings >> Community >> Community Configuration >> Member Profile Questions.

When paired with IdeaScale's group function, described in Configuring Group Auto-Assignment below, members are segmented into groups according to the response given for each profile question.
Help article on Workspace Profile Questions
Help article on Community Member Profile Question
Mapping Attributes to Profile Questions
After profile questions have been created, IdP attributes are mapped to them from the Single Signon Settings page.
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon
- Select the More option (three dots) beside the SSO name, then select Map Attributes from the dropdown.

- Map the attributes to create groups based on the profile questions created for the Workspace or community.

Example SAML Attribute:
<saml:Attribute Name="department"> <saml:AttributeValue>Finance</saml:AttributeValue> </saml:Attribute>
With Department mapped as the attribute entered in the Workspace Member Profile Questions or Community Member Profile Questions field, and the Group Criteria value set to HR, a member is automatically placed into the HR group. (TO BE VERIFIED — the sample SAML attribute value shown above is Finance, which does not match the HR value referenced in this example; the source content may contain an inconsistency between the two.)
Configuring Group Auto-Assignment
After SSO Profile Field Mapping is configured, groups are created and set to assign members automatically based on profile question responses.
Path: Workspace Homepage >> Navigation Panel >> Members >> Groups
- Create the user group.
- Enter the group's name and update any other settings.
- Switch to the Assignment Method.
- Select Auto Assignment based on Profile Criteria.
- Select the profile question response required for a member to be automatically added to the group.

Under Groups, group membership can also be managed manually, and the number of members in a particular group can be viewed.
Help article on Group assignment method
Exceptions
- Auto Assign by SSO Restriction: The Auto Assign by SSO setting under Group Settings for an IdP-mapped group switches on automatically the first time a member logs in via SSO and is added to that group. A Workspace Administrator cannot switch this setting on or off manually.
- IdP Group Attribute Requirement: SSO Group Attribute Mapping requires the Identity Provider (IdP) to send a group attribute in the SAML assertion. Without this attribute, groups cannot be created or assigned automatically using this method.
Frequently Asked Questions
What is the difference between SSO Group Attribute Mapping and SSO Profile Field Mapping?
SSO Group Attribute Mapping automatically creates and assigns groups directly from an IdP-supplied group attribute, with no manual group setup required. SSO Profile Field Mapping instead maps other IdP attributes to profile questions, requiring groups to be manually created and configured with Auto Assignment based on Profile Criteria.
Can a member be placed into more than one group at once through SSO Group Attribute Mapping?
Yes. If multiple values are supplied in the mapped group attribute, IdeaScale searches for each value and places the member into every corresponding group, creating a new group when necessary.
Can a Workspace Administrator disable Auto Assign by SSO for an IdP-mapped group?
No. The Auto Assign by SSO setting switches on automatically once a member logs in through SSO and is added to the group, and cannot be switched off by a Workspace Administrator. See Exceptions above.
Where can group membership be managed after groups are created through SSO mapping?
From Member Management >> Groups, where a Workspace Administrator can override or modify group membership and view the number of members in each group.
Related Articles
- Help Article for Workspace Single Sign-On Settings
- Help Article for SAML Single Sign-On at IdeaScale
- Help Article for Common SSO Questions
- Help Article for Workspace Profile Questions
- Help Article for Community Member Profile Questions
- Help Article for Group Creation
- Help Article for Member Management
Last Updated: August 17, 2026