Skip to main content

Step 3: Map roles

To provide users with authorization and access to System Manager, you must map the IdP user attributes and group memberships to the storage array's predefined roles.

Before you begin

  • An IdP administrator has configured user attributes and group membership in the IdP system.
  • The IdP metadata file is imported into System Manager.
  • A Service Provider metadata file for each controller is imported into the IdP system for the trust relationship.

About this task

In this task, you use System Manager to map IdP groups to local user roles.

  1. Click the link for mapping System Manager roles.
    The Role Mapping dialog box opens.
  2. Assign IdP user attributes and groups to the predefined roles. A group can have multiple assigned roles.
    Note
    The Monitor role is required for all users, including the administrator. System Manager will not operate correctly for any user without the Monitor role present.
  3. If desired, click Add another mapping to enter more group-to-role mappings.
    Note
    Role mappings can be modified after SAML is enabled.
  4. When you are finished with the mappings, click Save.