Skip to main content

2026-06-12 New feature: use holder group in UID script

The new feature

Now, on the Service provider configuration page, the holder group can now be used in the UID selection script.

Bear in mind

Please note the following points:

  • If there are multiple levels of folders, only the authorizations from the parent folder are inherited.

How to configure it?

The following components must be installed:

  • Federation addon 3.6.92 (or higher)

Let's look at an example

First of all, we check that we have a user with holder groups.

image.png

 

We can now confirm that the service provider has the option "" enabled.

image.png

 

We use the holderGroup attribute in the UID script.

image.png

 

Finally, we’re going to authenticate with the service provider and check the value of the UID attribute.

image.png

 

image.png


image.png