> For the complete documentation index, see [llms.txt](https://docs.cusna.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cusna.io/cloud-identity-platforms-integrations/enterprise-cloud-idps/group-mapping.md).

# Group mapping

With some type of external connectors, Cusna allows to define static rules to assign external users to a destination Group in Cusna, based on some criteria.

In general, the feature allows to statically define the mapping form a source group id (which definition depends on the IdP used) and the destination Cusna [Group](/service-management/groups.md).

{% hint style="info" %}
For most IdPs, you also have the option to make sure that only users that are mapped to a group are granted access to the service, by enabling the option **Authorize only members of mapped Groups**
{% endhint %}

### **Microsoft Entra (oAtuh)**

In case of Microsoft, it possible to crete rules that map the Azure Group ID into a Cusna Group. You can select the Microsoft Entra ID Group form a dropdown menu

<figure><img src="https://3426155342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDvdioCJduzKTpzAv3Sij%2Fuploads%2FVAFB5S08T9bPWq4mzZSZ%2Fimage.png?alt=media&amp;token=c2356a56-59e6-446e-9ad5-e64ac152f031" alt=""><figcaption></figcaption></figure>

### **Google (oAtuh)**

In case of Google, it possible to crete rules that map the Google Group  into a Cusna Group. You can select the Google Group form a dropdown menu.

<figure><img src="https://3426155342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDvdioCJduzKTpzAv3Sij%2Fuploads%2FwfZoQcj53vzx59oh41Ws%2Fimage.png?alt=media&amp;token=1f6f4a45-30f6-47bf-befb-b6fecbc1064f" alt=""><figcaption></figcaption></figure>

### **SAML**

In case of SAML integration, for most systems, it possible to crete rules that map the source Group  into a Cusna Group. You need to enter the SAML Group identifier manually in the Source Group ID input.

<figure><img src="https://3426155342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDvdioCJduzKTpzAv3Sij%2Fuploads%2FFsl5UnLl2nRC7PdKOpL6%2Fimage.png?alt=media&amp;token=74781be0-7414-4f66-a158-57043b4e17a9" alt=""><figcaption></figcaption></figure>

#### Microsoft Entra&#x20;

For Microsoft Entra ID, you need to enter the value of the Object ID of the Group that you can find the in the Azure Portal.&#x20;

<figure><img src="https://3426155342-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDvdioCJduzKTpzAv3Sij%2Fuploads%2FB3eqnybhQmeAOPElsfnj%2Fimage.png?alt=media&amp;token=fac668a2-5079-4925-9182-9f3c3794fd57" alt=""><figcaption></figcaption></figure>
