Importing and syncing users and groups at logon time
As an LDAP administrator, you can enable the import of users and their associated groups from a SAML 2.0-based identity provider (IdP) in your company into BMC Helix Portal at logon time.
Each time a user logs on to the BMC Helix Portal console:
- New users and groups are imported.
- Changes related to the existing users and groups are synced.
The imported users and groups are displayed in the same way as the manually created users and user groups, with the type External.
The imported users and groups are displayed on the User access > User groups page and the User access > Users page respectively.
To import and sync users and groups at logon time
Ensure that SAML is configured and user group sync is enabled. Contact BMC Support to configure Helix Single Sign-On as described in Configuring authentication.
- Use one of the following methods to import user details from the SAML assertion:
- Import users and groups along with their mapping:
To use this method, perform the following steps:- Create an external user with the same login ID as the LDAP admin user.
For more information, see Setting-up-users-for-console-access. - Assign the external user to a role with all permissions or at a minimum all permissions to the Identity Management Service application or service.
For more information, see Setting-up-roles-and-permissions. - Ask users to log on to the BMC Helix Portal console.
BMC Helix Portal updates the user and group membership in the following way:- Logged-in users are automatically created with the type External.
- Groups associated with the logged-in users are automatically created with the type External.
- Logged-in users are automatically mapped with the groups.
- Assign the imported groups to relevant roles with appropriate permissions.
- Create an external user with the same login ID as the LDAP admin user.
Import users with their mapping information: Groups need to be created manually before the import and permissions need to be assigned to the groups. Doing this permission assignment, ensures that all the imported users are automatically mapped to the groups with appropriate permissions the very first time. This method is also useful for syncing changes made to the users and groups.
To use this method, perform the following steps:
- Create user groups with the same name as the groups managed by your IdP.
For more information, see Setting-up-user-groups. - Assign the user groups to roles with appropriate permissions.
For more information, see Setting-up-roles-and-permissions. - Ask users to log on to the BMC Helix Portal console.
BMC Helix Portal updates the user and group membership in the following way:- Logged-in users are automatically created with the type External.
- The existing user groups are updated with the new details from the IdP and the type is changed to External.
- The user groups are automatically mapped to the logged-in users.
- Create user groups with the same name as the groups managed by your IdP.
- Import users and groups along with their mapping: