Creating Claim Mappings

After registering the SAML identity provider, view the Claims tab to map SAML claims to Directory Server claims. Directory Server supports several pre-defined claims that will be applied to the user's profile. View your SAML identity provider's settings to find the corresponding claim.

  1. In Laserfiche Directory Server, click Settings.
  2. Click the Identity Providers tab.
  3. In the left pane, click the name of your identity provider.
  4. Select the Claims tab.
  5. In the Claim Mappings section, type the attribute names you configured in your identity provider's configuration site. For example, the following image shows the custom attributes created in Salesforce, typed into the corresponding field names:

  6. Note: SAML attribute Name is needed for Directory Server claim mappings. SAML attribute FriendlyName will not work for claim mappings. To learn more about intercepting the SAMLResponse, navigate to Intercepting the SAML Response.

    Note: For more information on claim mappings, navigate to configuration pages for your specific SAML identity provider: Okta, Salesforce, Shibboleth, and Microsoft Entra ID.

  7. To add group claim mappings, see Group Claim Mappings.
  8.  To add custom claim mappings, see Custom Claims.
  9. Click Save to finish.
  10. Note: Claims are automatically updated in Laserfiche Directory Server when a user signs in based on the SAML token.