Once your Orchid Fusion VMS properties file and Identity Provider web interface have been configured, you need to assign Fusion permissions for each of the groups you created within the IdP.

  1. With SAML fully configured, restart the Orchid Fusion VMS service.
  2. Now you need to associate your Orchid Fusion VMS Permissions Groups with the Identity Provider’s groups.
    1. Log into Fusion as an Administrator.
    2. Go to the Permission Groups screen.
    3. For each of your IdP groups that need to log into Fusion, do the following:
      1. Click the Add Permission Group button. (You may add these new groups to an existing Permission Group instead, if desired.)
      2. Enter a name and description for the new group.
      3. Go to the External Group Mapping section. (If this section does not appear, there must be a problem with the SAML configuration. The configuration may be incomplete or inaccurate, or you may have forgotten to restart the Fusion service.)
      4. Click in the Domain field and enter the name of the domain in which your target users exist. (This should match the value you configured as saml.common.setting.domain in the fusion.properties file.)
      5. Click in the Group field and enter the name of a group in which your target SAML users exist. (This should match the name of a group from any one of your configured IdPs.)
      6. Click the Add icon to add this new external group.
      7. Grant and revoke abilities and access to cameras, as needed.
      8. Click the Save button to save the Permission Group.

In the following example, we have a Permission Group that provides Administrator access to users in the orchid-hybrid-admins SAML group. (In this case, that’s the name of a Google Workspace group):

For additional details on adding external Permission Groups, please refer to the Orchid Fusion/Hybrid Administrator Guide.

Feedback

Was this helpful?

Yes No
You indicated this topic was not helpful to you ...
Could you please leave a comment telling us why? Thank you!
Thanks for your feedback.

Post your comment on this topic.

Please do not use this for support questions.
IPConfigure Technical Support

Post Comment