Forum Discussion
spalande
May 01, 2024Nacreous
Have you tried using LDAP qurey feature that will query the LDAP server to get the group assignment and then based on that you can create different network access profiles using separate VPN pool.
- PShakunthalaMay 01, 2024Nimbostratus
Thanks spalande For your response. I was able to solve the problem by adding an expression in advanced resource assign tab.
expr {[mcget {session.saml.last.attr.name.http://schemas.microsoft.com/ws/2008/06/identity/claims/groups}]
contains "Õe66c3bf-e0ee-40d4-9649-2534647f2378"}