Skip to main content
All CollectionsIntegrations
Introduction: OIDC Group Mapping
Introduction: OIDC Group Mapping

Manage Dispel group membership from an OIDC compliant identity provider

P
Written by Pete Pickerill
Updated over a month ago

Dispel streamlines group membership management by supporting direct mapping between groups in identity provider (IdP) groups and Dispel groups. When groups are mapped, changes made in the IdP are automatically reflected in Dispel. For example, adding or removing users from an IdP group automatically updates their membership in the corresponding Dispel group. This integration allows organizations to manage users and groups through a single, centralized solution that is intuitive and inherently auditable.

Supported Identity Providers

  • Microsoft Entra

Key Benefits of OIDC Group Mapping

  1. Centralized Access Management

    • Administrators manage user roles directly in the IdP, eliminating the need to configure permissions in individual applications.

    • Application permissions are tied to IdP groups, ensuring a consistent and streamlined workflow.

  2. Automated Provisioning

    • User access is automatically updated when changes are made in the IdP.

    • Adding a user to an IdP group instantly grants them appropriate permissions in linked applications, while removal revokes access.

  3. Enhanced Security

    • Centralized controls minimize risks of misconfigurations and stale permissions.

    • Permissions are continuously synchronized with IdP group memberships, ensuring users only have the access they need.

  4. Scalability

    • Permissions are managed at the group level, making it easy to apply changes across large user bases.

    • Adding or removing users from a group updates access for multiple applications in bulk, simplifying management for growing organizations.

  5. Improved User Experience

    • Users automatically receive permissions based on their group assignments, requiring no additional configuration.

    • Once authenticated, they gain seamless access to applications with the correct roles already in place.

  6. Compliance and Audit Readiness

    • Role-to-group mapping ensures clear and consistent audit trails.

    • IdPs often log group membership changes, making it easier to trace and verify access permissions for compliance purposes.

By integrating OIDC group mapping, organizations gain a scalable, secure, and efficient way to manage access, while simplifying compliance and providing users with a seamless experience.

Next Steps

Did this answer your question?