Brightspot CMS User Guide

Associating SSO groups with Brightspot roles


In most scenarios, single sign-on servers associate users with groups. Similarly, most publishers associate Brightspot editors with roles. As a best practice, you should associate the SSO groups with the corresponding Brightspot roles. This practice ensures that when an editor successfully logs in through single sign-on, Brightspot associates the editor with the correct role.

Caution
If a group on the SSO server is not associated with a Brightspot role, all users associated with that group are denied login to Brightspot (even if they pass authentication on the SSO server). Ensure all groups on the SSO server are appropriately associated with Brightspot roles.
Warning
If you do not configure any group-role associations, then any editor passing SSO authentication is granted login to Brightspot with no role, which may be the administrator role. Ensure you configure at least one group-role association.

To associate SSO groups with Brightspot roles:

  1. Click menu > Admin > Sites & Settings.
  2. Under Legacy Settings, click Saml. The Edit Saml widget appears.
  3. Under Groups to Roles, do the following:

    1. Click add_circle_outline. A form appears.

      Associating SSO groups with Brightspot roles

    2. In the Group field, enter a group existing on the SSO server.
    3. In the Role field, select an existing Brightspot role.
    4. Repeat steps a–c to associate additional groups to roles.
  4. Click Save.

Referring to the previous illustration, an editor signing on through SSO and has the group ssoBrightspotEditors receives all the permissions in Brightspot associated with the role Editors.

Previous Topic
Activating single sign-on
Next Topic
Reviewing SSO logins
Was this topic helpful?
Thanks for your feedback.