| Flag | Description |
|---|---|
--auth-saml-enabled | Enable SAML authentication. |
--auth-saml-url | The URL to the IdP metadata file. |
--auth-saml-label-rules='{"membership": "groups"}' | This extracts the membership attribute from the SAML assertion into the label saml.omni.sidero.dev/groups/groups |
memberhip into the Omni user’s identity resource label with the
prefix saml.omni.sidero.dev/groups
Restart Omni, and log in using SAML. If you navigate to Settings > Users, you will now see your groups in a label.
If your SAML attribute memberships contains the values group1 and group2 you will see the following two labels (the interface omits the prefix saml.omni.sidero.dev)