====Group Mapping==== **Group Mapping** allows you connect the users and/or groups from your SAML source to the correct permission levels in ARDI. You can set this up by going to **Administration|SAML Authentication Settings** and clicking on one of your SAML servers. ===Adding a Mapping=== {{groupmapping.png}} To add a group mapping, simply type the name of the group (or in some cases such as //Azure// or //Entra AD// the GUID of the group), and choose the level of access you want that group to have. You can also add user names in this section. Note that this must match the unique ID from the SAML source, which is often the users email address. ===Deleting a Mapping=== Press the trash-can icon to the right of the mapping to delete it. ===Defaults=== By default, all users are permitted to read data. To change the default level, add a group named '*' and assign the correct level. For example, you can deny access to ARDI by adding a group called '*' and the permission level 'None'. ===See Also=== You might also be interested in [[Property Mapping]].