After you have configured SSO logins for Ping Identity, you can further configure Ping to manage permissions for your Canary Console users, such as their Flock access and whether they are Global Admins. This guide will walk you through the Ping changes you need to make to support IdP-managed permissions.
Change Summary
Inside your Ping Admin Console, we will assign three attributes to each user based on their group affiliation. This allows Ping to manage your Canary Console user permissions. The three attributes are: is_global_admin, managed_flocks and watched_flocks.
For more information on the IdP-managed permissions feature and the associated SAML attributes, see this article.
All the steps below take place in your Ping account. Login to your Ping Identity WebUI with a user who is able to modify the Thinkst Canary SAML application.
Step 1: Create User Groups.
You'll need 3 groups to manage the common kinds of user types. These aren't strictly required and you may choose to only have administrators, for example.
In our example we'll create these 3:
Project Bird Admins - These users will have full control over the Canary Console.
Project Bird Managers - These users have write control over specified Flocks.
Project Bird Viewers - These users have read-only control over specified Flocks.
You may choose to expand the manager and watcher groups into more granular sets. For example, if you'd prefer to give 2 users control over different selections of Flocks, multiple groups would be required to differentiate them.
Head over to Directory, then Groups and finally hit the plus icon button.
At this point, you'll also want to assign your users to these groups, based on the level of access you'd prefer them to have.
To do this, click on one of your groups, then select the Users button, finally hit the pencil icon.
Step 2: Assign groups
With our groups created, we'll next assign your Canary Console SAML App to these groups, to give the users the ability to log in.
At this point, the users will land on the Canary Console with no permissions, for now.
Step 3: Add Attribute Mappings
With our groups created and assigned, we'll next create Attribute Mappings. These will be small rules used to assign a permission / attribute to our groups when the users log in.
Switch over to the Attribute Mappings tab, and select the pencil icon.
Here we'll add 3 attributes to cover each attribute required. Hit the Add button 3 times, and create entries for the 3 Attributes; you'll want to ticket the required checkboxes too.
Finally, we'll hit the advanced expression button (the cog icon) to create the logic that decides which users should get the attributes.
Once complete simply hit save and try logging in!
is_global_admin
This entry covers your Global Admin users, if the user belongs to the group Project Bird Admins , they will receive the value "true", else they will receive a "false" value. Please modify the group name to match your environment.
#data.indexOf(user.memberOfGroupNames, 'Project Bird Admins') >= 0managed_flocks
This entry covers your Flock Managers, if the user belongs to the group Project Bird Managers , they will receive access to the list of Flock ID's you specify, else they will receive a blank value.
Please modify the group name to match your environment as well as the list of Flock ID's.
#data.indexOf(user.memberOfGroupNames, 'Project Bird Managers') >= 0 ? 'flock:default' : ''wached_flocks
This entry covers your Flock Watchers, if the user belongs to the group Project Bird Viewers , they will receive access to the list of Flock ID's you specify, else they will receive a blank value.
Please modify the group name to match your environment as well as the list of Flock ID's.
#data.indexOf(user.memberOfGroupNames, 'Project Bird Viewers') >= 0 ? 'flock:default' : ''
Take note that multiple Flocks should be declared in comma separated format
without a space. i.e:
flock:default,flock123,flock:456
You may want an additional statement to cover a 2nd group with individual specified Flocks. To handle this, we'll create a seperate entry, refrencing the new group name and their access.
#data.indexOf(user.memberOfGroupNames, 'Project Bird Viewers 2') = 0 ? 'flock:456,flock:789' : ''
How do I find my Flock ID?
Flock ID's can be obtained by clicking on a Flock name within your Canary Console, then hiting the cog icon to the top right to get to it's settings.
Finally the Flock ID will be present in this menu.