Overview
If you've set up SAML as your authentication method in the main plan, you can define policies to assign users to the appropriate managed plan automatically. For example, any user with SAML attribute "department" that has a value of “finance” can be assigned to the managed plan owned by the Finance department.
To set up a user movement policy
- On the Manage plans screen, select Configure user movement policy.
If this is the first time you've set up a policy, you'll see a pre-filled template. The template has a section corresponding to each of the managed plans. Use the attribute and values fields to set the policy for a specific managed plan.
The user movement policy only supports plan-level SAML configurations and is incompatible with domain-level SAML setups. If you’ve already configured a user movement policy, switching to domain-level SAML won’t be possible.
Add attributes
You can use any of the following attributes:
Variable | Schema name | Name formats supported |
---|---|---|
Variable Title | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/title | Name formats supported
|
Variable Department | Schema name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/department | Name formats supported
|
Variable Cost center | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/costcenter | Name formats supported
|
Variable Primary phone number | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/primaryphone | Name formats supported
|
Variable Mobile phone | Schema name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone | Name formats supported
|
Variable Manager | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/manager | Name formats supported
|
Variable Company | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/company | Name formats supported
|
Variable Country | Schema name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/country | Name formats supported
|
Variable Job role | Schema name http://schemas.microsoft.com/ws/2008/06/identity/claims/jobrole | Name formats supported
|
Variable Given name | Schema name givenname | Name formats supported
|
Variable Surname | Schema name surname | Name formats supported
|
Use custom attributes
You can also use custom attributes by mapping them to any of these ten attributes. New users that don’t have a match are placed in the main plan.
Variable | Schema name | Name formats supported |
---|---|---|
Variable customField1 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield1 | Name formats supported
|
Variable customField2 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield2 | Name formats supported
|
Variable customField3 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield3 | Name formats supported
|
Variable customField4 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield4 | Name formats supported
|
Variable customField5 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield5 | Name formats supported
|
Variable customField6 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield6 | Name formats supported
|
Variable customField7 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield7 | Name formats supported
|
Variable customField8 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield8 | Name formats supported
|
Variable customField9 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield9 | Name formats supported
|
Variable customField10 | Schema name http://schemas.smartsheet.com/ws/2021/01/identity/claims/customfield10 | Name formats supported
|