IDP Specific

Why are group or role values not being mapped correctly after Okta SSO?

4 views 0

Probable Cause:

Okta is not configured to send group/role claims, or the miniOrange plugin’s role mapping is not aligned with the claim sent by Okta.

Solution:

  1. In Okta Admin → Applications → your WordPress appSign OnEdit.
  2. Under Attribute Statements, add:
    • Name: groups
    • Expression: user.getGroups (eg.xyz)
  3. Save the application settings.
  4. In WordPress → miniOrange SAML SSO → Role Mapping, map the incoming group values to WordPress roles.
  5. Save and test with a user who belongs to the group.

Still need help?

Contact us at samlsupport@xecurify.com

Was this helpful?


Hello there!

Need Help? We are right here!

support