Add multiple users in an assigned group to sign in to the TrendAI Vision One™ console using a corporate identity provider (IdP) solution.
IdP-Only SAML Group Account users must sign in via their IdP to access TrendAI Vision One™.
Once TrendAI Vision One™ and the IdP
have exchanged SAML metadata documents and established a trust relationship, TrendAI Vision One™ can accept
assertions coming from the IdP and use them to authenticate a user into TrendAI Vision One™. In addition to
the metadata document, TrendAI Vision One™ requires instructions for interpreting the data in the
assertion from the IdP in order to know how to authenticate users. This is done
using mapping and claims.
-
Mappings are used to associate attributes in TrendAI Vision One™ with the user attributes in your IdP.

Note
Attributes might appear under different names in different IdPs, though this does not affect mapping. -
Claims are pieces of information about the user provided by the IdP in an assertion.
Important
|
Procedure
- Go to .
- Click Add Account.
- Select IdP-Only SAML Group.
- Specify a Group name for the IdP-Only SAML Group Account.
- Select a Role.To create a custom user role, click Create a custom role in User Roles.For more information, see User Roles.

Important
Creating a custom role leaves the User Accounts screen and discards all recent changes. - (Optional) Specify a Description for the user account.
- Select an IdP from which to select groups that can access the TrendAI Vision One™
console.You can find all the IdPs that have been added in Identity Providers in the drop-down list, but only the IdPs that are configured to support IdP-Only SAML Group Account are available to select.If no IdPs appear, go to and configure one or more existing IdPs to support IdP-Only SAML Group Accounts. There is no downtime associated with this process.
- In the Value field, list the identifiers of up to 10
IdP-defined groups for the account that can access TrendAI Vision One™.The Group attribute field populates automatically based on the IdP you selected.
- (Optional) If you want to add groups from another IdP for the user account, you
can click Add Group in Another Identity Provider and
specify group identifiers for a different IdP.If you need to add more than 10 groups from the same IdP, you must add a new IdP-Only SAML Group Account.
- Click Add.
- (Optional) On the User Accounts screen, enable or disable added accounts using the Status toggle.
