Applies to
- Enterprise
Capabilities
Who can use this capability
- System Admin
Set a user movement policy for use with Enterprise Plan Manager (SAML only)
Who can use this?
Plans:
- Enterprise
Permissions:
- System Admin
Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.
Overview
If you've set up SAML as your authentication method in the main plan, you can define policies to assign users to the appropriate managed plan automatically. For example, any user with SAML attribute "department" that has a value of “finance” can be assigned to the managed plan owned by the Finance department.
To set up a user movement policy
- On the Manage plans screen, select Configure user movement policy.
If this is the first time you've set up a policy, you'll see a pre-filled template. The template has a section corresponding to each of the managed plans. Use the attribute and values fields to set the policy for a specific managed plan.
The user movement policy only supports plan-level SAML configurations and is incompatible with domain-level SAML setups. If you’ve already configured a user movement policy, switching to domain-level SAML won’t be possible.
Add attributes
You can use any of the following attributes:
Variable | Schema name | Name formats supported |
---|---|---|
Title | http://schemas.smartsheet.com/ws/2021/01/identity/claims/title |
|
Department | http://schemas.xmlsoap.org/ws/2005/05/identity/claims/department |
|
Cost center | http://schemas.smartsheet.com/ws/2021/01/identity/claims/costcenter |
|
Primary phone number | http://schemas.smartsheet.com/ws/2021/01/identity/claims/primaryphone |
|
Mobile phone | http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone |
|
Manager | http://schemas.smartsheet.com/ws/2021/01/identity/claims/manager |
|
Company | http://schemas.smartsheet.com/ws/2021/01/identity/claims/company |
|
Country | http://schemas.xmlsoap.org/ws/2005/05/identity/claims/country |
|
Job role | http://schemas.microsoft.com/ws/2008/06/identity/claims/jobrole |
|
Given name | givenname |
|
Surname | surname |
|
Use custom attributes
You can also use custom attributes by mapping them to any of these ten attributes. New users that don’t have a match are placed in the main plan.
Variable | Schema name | Name formats supported |
---|---|---|
customField1 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield1 |
|
customField2 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield2 |
|
customField3 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield3 |
|
customField4 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield4 |
|
customField5 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield5 |
|
customField6 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield6 |
|
customField7 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield7 |
|
customField8 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield8 |
|
customField9 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield9 |
|
customField10 | http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield10 |
|