Once Deep Discovery Email Inspector and the identity provider have established a trust relationship, Deep Discovery Email Inspector can access the user identities on the identity provider's directory server. However, before Deep Discovery Email Inspector can actually perform user authentication and authorization using the user identity information, you need to configure account types and SAML groups using groups, roles and claims.
The following provides a configuration overview to map a SAML account from identity provider to a user role in Deep Discovery Email Inspector:
-
Create user accounts.
-
Create user accounts.
-
Create user groups and assign user accounts to the groups.
For more information, see the documentation that comes with your identity provider.
-
-
In Deep Discovery Email Inspector, create SAML groups with the specified roles and claims.
For more information, see Configuring SAML Groups.