Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Map identity claims to roles
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Connect LDAP or Active Directory
Next
Secure a Buttons deployment →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Access/SSO/Map identity claims to roles

Map identity claims to roles

Once a connection exists, Role mappings decide which Buttons roles a person gets when they sign in through it: based on claims their identity provider actually sends, re-evaluated every time they sign in.

Before you begin#

  • An SSO connection already configured: see Connect a generic OIDC provider or Connect LDAP or Active Directory.
  • At least one Role already created: see Create roles and assign permissions.

Add a mapping#

  1. Open the connection and find Role mappings: "Map ID-token claims to local roles. Changes save immediately."
  2. Enter a Claim name (for example, groups), a Claim value matching what your provider actually sends, and the Local role to grant when it matches.
  3. Add as many mappings as you need: several claim values can point at the same role, and one claim value can be reused across several mappings pointing at different roles.
Use Test mappings to paste a sample of decoded ID-token claims and see which roles it would grant, without needing a real sign-in to check your work.

Note

GitHub doesn't offer role mappings at all: it uses its own Required Organization setting instead. Google, Microsoft Entra ID, Okta, and LDAP each show their own short caveat about how their group claims actually behave; read it before assuming your claim name is right.

Understand when sync actually runs#

Role sync isn't a one-time provisioning step: it runs on every sign-in, comparing what the current login's claims justify against the SSO-granted roles the person already has, and adds or removes roles to match. A role this connection previously granted can be taken away on a later login if the claim that justified it is no longer present.

What happens when a claim is missing vs. malformed#

These are genuinely different outcomes:
  • A claim is simply absent from a login's claims (the person's group membership changed, for example): the role tied to that specific mapping is removed on this login, same as any other reconciliation. They are not able to keep their last-known access.
  • A claim's shape is malformed or ambiguous: for example, a value your mapping expected as a string arrives as a number or object, or Microsoft Entra ID sends a group "overage" claim because there are too many groups to list: the entire sign-in is rejected outright, with the message "Sign-in could not determine your access. Please contact your administrator." Buttons refuses to guess at partial or unreliable data rather than granting or revoking access on it.

Override a role manually#

An admin can still grant a role to an SSO-authenticated user by hand, the same way as any other user. A manually granted role survives every future sync, even if the identity provider's claims never grant it: Buttons tracks manual grants separately and never removes them through reconciliation.
The reverse isn't quite symmetric: if a role is still being actively granted by a live claim mapping, removing it from the user manually won't make it stick: the next sign-in re-grants it via that mapping. To durably take a role away from someone whose claims currently justify it, change or remove the mapping itself rather than just unassigning the role.

Delete a mapping#

Deleting a mapping shows an explicit warning: "Delete the mapping {claim}={value}? SSO role assignments granted by this mapping will be removed immediately. Manual role assignments are not affected." Manually granted roles are never touched by deleting a mapping.

What happens when you disable or remove a connection#

Disabling or deleting an SSO connection takes effect immediately, not just for future logins:
  • Every role contribution from that connection is removed at once, and any role left with no other reason to exist (not manually granted, no other mapping still justifying it) is dropped.
  • Every active session signed in through that connection is signed out immediately.
  • The user's account itself isn't deleted: it persists as a local account with no SSO-derived roles, effectively an orphan until it's given local access some other way.

What happens if a user is removed from the identity provider itself#

Buttons has no way to know this happened: there's no background check or scheduled sync against your provider. An already-active session for that person keeps working until it naturally expires or an admin kicks it manually. Nothing changes on the Buttons side until they try to sign in again, at which point the failure happens on your identity provider's end, outside Buttons' control.

If you get stuck#

What you see
What to try
A user lost a role they used to have.
Check whether the claim that justified it is still present in their current login: sync runs every sign-in and removes roles that no longer match.
A sign-in fails with "Sign-in could not determine your access."
A claim arrived in an unexpected shape (or, for Microsoft Entra ID, a group-overage claim): check your provider's claim configuration, not just the mapping itself.
You manually assigned a role but it keeps disappearing.
A live claim mapping may not be granting it, and something else is removing it: check for a mapping actively removing that role, not just add one back manually.
You removed a role from a user but it came right back.
A claim mapping is still actively granting it: adjust or remove the mapping itself rather than the user's role assignment.
You disabled a connection and users got signed out unexpectedly.
That's expected: disabling a connection immediately revokes its role contributions and kicks every session it authenticated.
Someone was removed from the identity provider but still has an active Buttons session.
That's expected until the session naturally expires: kick it manually from Understand and manage sessions if you need it ended sooner.

Where to go next#

  • Get started with SSO
  • Create roles and assign permissions

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful