Managing User Roles and Permissions with Aliases - manage-netcloud-access/Managing-User-Roles-and-Permissions-with-Aliases

Managing Identities and Access for NetCloud

NetCloud Feature
Management > Users
Security > NetCloud Access > Federated ID
ft:locale
en-US
ft:sourceName
Paligo_Prod
Document Type
Admin Guide
Configuration Guide

Aliases are used for assigning your SSO users to a specific subaccount and role. Aliases simplify the process of managing user accounts and roles for SSO.

SSO-user roles and permissions can be created, edited and deleted on the Alias tab in NetCloud Manager on the Account > SAML Single-Sign On page. Working with Aliases requires Administrator or Full-Access User permissions.

Creating and using an Alias is a two-step process.

  • Creating the Alias

  • Using Aliases in a NetCloud Manager SSO Configuration

Note

Ther is currently no limit on how many Aliases can be created in an account.

Creating aliases
  1. Log into NetCloud Manager.

  2. Select Account in the left-side navigation panel.

  3. Account > SAML Single-Sign On > Alias

  4. Select Add to open the Add Alias drawer and add a new alias.

    sso-saml-add-alias.png
    1. Add a name for the alias in the Alias Name field.

    2. Select a role for the alias from the Role drop-down list.

    3. Select a subaccount for the alias from the Subaccount drop-down list.

    4. Select Add to finish adding the new alias.

Editing aliases
  • Select an alias from the grid and then select the ellipsis icon (blue-ellipsis.png) to edit or delete the selected alias.

    sso-saml-alias-edit.png

    Note

    When an alias is edited, only the role and subaccount can be changed. The Alias Name can't be modified.

Using aliases in a NetCloud Manager SSO configuration
  1. Follow the configuration steps in either example, Mapping SSO Settings between an Okta IDP App and NetCloud Manager or Mapping SSO Settings between an Okta IDP App and NetCloud Manager until you reach the second page of the Add/Edit Identity Provider wizard.

  2. Add the Alias in the Alias field.

    sso-saml-mappings-alias.png
  3. Complete the remaining configuration steps as shown in Mapping SSO Settings between an Okta IDP App and NetCloud Manager or Mapping SSO Settings between an Okta IDP App and NetCloud Manager.

Alias options based on previous SSO configurations
  • If you used NetCloud SSO with forced permissions before the Alias feature was released, you will have the recommended option to switch to the Alias feature.

    sso_saml_permissions.png
  • If you have never used NetCloud SSO, you will only have the option to select Alias for the user and account permission mapping.