Checking your SAML attribute mappings for Ideagen Hub
Who is this article for?
Users who want to learn to check their SAML attribute mappings in Ideagen Hub.
No elevated permissions are required.
As part of the Ideagen Hub migration, customers using Single Sign-On (SSO) must ensure that Ideagen Hub is configured with the correct SAML attribute mappings to allow your Identity Provider (IdP), such as Azure AD or Okta, to correctly identify users and enable a smooth SSO experience.
1. Understanding what we need from you
We only require the SAML claim values for the following two attributes:
- preferred_username (user login name)
If you are using default Azure AD mappings, no action is usually required. If you have customised these mappings, we need the updated claim values from you.
2. Reviewing default Azure AD attribute mappings
If you have not changed the defaults in Azure AD, the mappings are typically:
- preferred_username →
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name - email →
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
If your setup differs from this, please follow the steps below.
3. Finding your SAML attribute mappings
To locate your SAML attribute mappings, follow these steps:
- Sign in to your IdP admin console, such as Azure AD (Microsoft Entra ID), Okta, or Ping Identity.
- Navigate to the SAML attribute or claim mappings for the application used to connect to Ideagen Hub.
4. Locating the attribute mappings page
To find the attribute mappings page, follow these steps:
- Look for a section labelled Attributes, Claims, or Attribute Statements.
- In Azure AD, navigate to Single sign-on, then select Attributes & Claims.
- In Okta, navigate to Applications, then select Sign On, then select Attribute Statements.
5. Finding the required attributes
To identify the required attributes, follow these steps:
- On the mappings page, locate the entries for preferred_username (or user login name) and email.
- Note that each attribute will have a claim name (often a long URL).
6. Sharing the claim values with Ideagen
To provide your claim values, follow these steps:
- For each attribute, copy the full claim name (the long URL).
- Send these two values to your Ideagen contact.
We will configure your Ideagen Hub tenant to match your IdP during the migration.
7. Preparing the information to send
Please provide:
- The claim value for preferred_username
- The claim value for email
Note: If you are unsure whether your mappings are custom or where to find them, your Ideagen contact can help guide you.