Map custom LDAP user and group attributes to the EAA directory
In your native directory, identify the custom groups and object classes, then
configure them in the EAA Management Portal.
When you use the EAA IdP between your LDAP
environment and service provider for SAML and SaaS applications, you can map both the
EAA default and custom attributes to the LDAP directory for both groups and users. This
is also known as OpenLDAP custom schema support.
How to
Identify the custom group and
custom object class for the user and group in your native LDAP directory
server.
Return to EAA Management Portal.
Open the Directory in EAA. From the top menu bar click Identity > Directories.
Navigate to the Directory you want to configure with a custom LDAP group or
user attribute and click the Configure (gear) icon > Show additional attributes > User attributes or Group attributes.
For Group attributes,
In the Group object
classes field, enter the LDAP custom group name. For
example, <YourCustomGroupName>
In the Search
filter field, enter the group object class as
objectClass=<YourCustomGroupName>).
User attribute mapping of Search filter and Group object classes in
EAAUser attribute mapping of Search filter and Group object classes in
the LDAP
For User attributes,
In the User object
classes field, enter the LDAP custom user name. For
example, <YourCustomUserName>
In the Search
filter field, enter the group object class as
(objectClass=<YourCustomUserName>).
Return to the directory card and
sync the changes to the directory in EAA.
From the top menu bar click Identity > Directories.
Navigate to the
Directory you modified and click the Sync
icon.
Verify the custom user or group
changes are in effect. Click the Users or Groups
icon.