# Managing Workplace Search Source Role access using SAML meta data

**URL:** <https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603>\
**Category:** Elastic Search\
**Created:** [July 14, 2021, 3:05am UTC](https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603 "2021-07-14T03:05:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt\_elastic](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@matt\_elastic](https://discuss.elastic.co/u/matt_elastic)\
**Post date:** [July 14, 2021, 3:05am UTC](https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603/1 "2021-07-14T03:05:46Z")

</div>

I have successfully hooked up SAML to a workplace search cloud instance and can succesfully setup access based on the username and email attributes. I want to however use the groups attribute.

I'm using Azure AD and I have confirmed the attribute is being sent mapped via elasticsearch.yml file: attributes.groups: "[http://schemas.microsoft.com/ws/2008/06/identity/claims/groups](http://schemas.microsoft.com/ws/2008/06/identity/claims/groups)"

I've been reading I can tap into the attributes using the metadata but I can't seem to work out the correct syntax. Anyone know what the trick is to get this to work?

---

<div class="post-metadata">

**Author:** ![ross.bell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ross.bell/32/77559_2.png) [@ross.bell](https://discuss.elastic.co/u/ross.bell)\
**Post date:** [July 14, 2021, 1:27pm UTC](https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603/2 "2021-07-14T13:27:23Z")

</div>

Hey @matt_elastic,

Have you seen this documentation: [Configuring SAML single-sign-on on the Elastic Stack | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html#saml-es-user-properties)? You should be able to configure SAML _groups_ attribute data to map to roles in Elasticsearch. Then, you can make use of those Elasticsearch roles in Workplace Search role mappings: [User Management and Security | Workplace Search Guide [7.13] | Elastic](https://www.elastic.co/guide/en/workplace-search/current/workplace-search-security.html#role-mapping).

I hope that helps. If you're still running into issues, please post whatever configuration you're using and the incorrect result you're observing, omitting or redacting anything sensitive.

Thanks  
Ross

---

<div class="post-metadata">

**Author:** ![matt\_elastic](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@matt\_elastic](https://discuss.elastic.co/u/matt_elastic)\
**Post date:** [November 12, 2021, 6:26am UTC](https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603/3 "2021-11-12T06:26:46Z")

</div>

Hi Ross, I finally managed to get time to revisit this and get it all working. Your information assisted me using the new 7.15 doco to config it. The bit i was missing was creating the elastic role which i could then utilise in workplace search to link to the group.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:31am UTC](https://discuss.elastic.co/t/managing-workplace-search-source-role-access-using-saml-meta-data/278603/4 "2022-11-04T08:31:27Z")

</div>


