---
title: "Mapping User Groups"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35463665/Mapping%20User%20Groups"
format: markdown
---
> ⚠️ **Note**
> ⚠️ 
> ⚠️ The map user groups functionality is configured through the SSO Portal, but it applies to Infoblox Portal users only.

<span style="color: #000000">The </span>**<span style="color: #000000">Map Groups</span>**<span style="color: #000000"> section allows you to automatically assign groups from your IdP (Identity Provider) to the Infoblox Portal groups. Based on your business requirements, you can choose a desired region, such as the US (United States) or EU (European Union) region. Depending on the selected region, you can add IdP user groups or Azure group IDs and map them to the respective Infoblox Platform user groups. Group mapping also requires that a “groups” attribute to be sent to the SAML response from your IdP.  Ensure that you populate the “groups” attribute with the IdP user groups or Azure group IDs that are assigned to your IdP users.</span>

<span style="color: #000000">When users sign in and are in the target</span> <span style="color: #000000">IdP user group or Azure group ID</span><span style="color: #000000">, they will automatically be assigned the </span><span style="color: #000000">Infoblox</span><span style="color: #000000"> Portal groups. If the user did not previously have a user account in the </span><span style="color: #000000">Infoblox</span><span style="color: #000000"> Portal, they will automatically be created and assigned groups in your company's </span><span style="color: #000000">Infoblox</span><span style="color: #000000"> Portal account.</span>

<span style="color: #000000">To configure user mapping, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span>[<span style="color: #000000">https://sso.infoblox.com/</span>](https://sso.infoblox.com/)<span style="color: #000000">.</span>
2. <span style="color: #000000">On the </span>**<span style="color: #000000">3rd Party IDP</span>**<span style="color: #000000"> page of the Infoblox SSO Portal, go to</span> the <span style="color: #000000">**Map Groups **</span><span style="color: #000000">section</span><span style="color: #000000">.</span>
3. From the Region drown-down menu, choose EU to map user groups in the EU region and choose US to do so in the US region. The SSO portal displays all regions by default.
4. In the respective region, click Add, and then enter the IdP group name or the Azure group ID in the text box:
  - **IDP USER GROUP**: For OKTA federation.
  - **AZURE GROUP ID**: For Azure AD federation
    **<span style="color: #000000">Note</span>**<span style="color: #000000">: Ensure that you enter the IdP group name </span>or Azure group ID<span style="color: #000000"> you have configured in your SAML application. You can find the IdP group name/ID at your IdP. Azure AD will only send the groups’ Azure Group ID in the SAML Assertion. Therefore, IDP group names are not used when federating with Azure AD.</span>
    <span style="color: #000000">The following restrictions apply to the IdP group names:</span>
    - <span style="color: #000000">The name cannot be empty.</span>
    - <span style="color: #000000">The length must be less than or equal to 253 characters.</span>
    - <span style="color: #000000">Valid characters include the following: a-z, A-Z, 0-9, -, .</span>
    - <span style="color: #000000">Must begin with an alphanumeric character.</span>
    - <span style="color: #000000">Must end with an alphanumeric character.</span>  
<span style="color: #000000">If your IdP group names do not meet the above restrictions, you will receive an error when you try to add the group mapping entries.</span>
5. <span style="color: #000000">From the </span>**<span style="color: #000000">Infoblox USER GROUP</span>**<span style="color: #000000"> drop-down list, choose the desired Infoblox User Group to </span>map to the respective IdP user group or Azure group ID<span style="color: #000000">. You can also use the search option by entering the name of the Infoblox user group to find a match. Repeat this process </span>for each IdP group or Azure group ID<span style="color: #000000"> as necessary to create multiple mappings. You can map multiple IdP groups to a single Infoblox user group.</span>  
<span style="color: #000000">For example, if you map an IdP user group "</span>*<span style="color: #000000">idp-group</span>*<span style="color: #000000">" to a Infoblox user group "</span>*<span style="color: #000000">ib-ddi-admin</span>*<span style="color: #000000">," any user who signs in to the </span><span style="color: #000000">Infoblox</span><span style="color: #000000"> Portal and belongs to the "</span>*<span style="color: #000000">idp-group</span>*<span style="color: #000000">" group will automatically be added to the "</span>*<span style="color: #000000">ib-ddi-admin</span>*<span style="color: #000000">" group.</span>
6. <span style="color: #000000">Click </span>**<span style="color: #000000">Save </span>**<span style="color: #000000">to save the mappings.</span>
7. <span style="color: #000000">After you have configured the SAML application and mapped user groups, you can complete the following configuration:</span>
  1. [<span style="color: #000000">*Testing 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367251)
  2. [<span style="color: #000000">*Activating 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463635)
  <span style="color: #000000">You can also perform the following after you set up 3rd party IdP authentication:</span>
  - [<span style="color: #000000">*Deactivating 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005)
  - [<span style="color: #000000">*Resetting 3rd Party IdP*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367439)
  - [<span style="color: #000000">*Adding a Chiclet for IdP-initiated SSO (OKTA)*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35431099)
  - [<span style="color: #000000">*Adding an IdP Application to Microsoft Azure*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367488)