Map identity provider groups to Docker teams
Group mapping synchronizes groups from your identity provider (IdP) with teams
in your Docker organization. For example, when you add a developer to the
moby:backend group in your IdP, Docker adds them to the backend team in the
moby organization.
Use group mapping to manage team membership through SAML SSO, SCIM, or both.
TipUse group mapping to add users to multiple organizations or teams. To assign each user to one organization or team, you can use SCIM user-level attributes.
Prerequisites
Before you begin, you must have:
- SSO configured for your organization
- Administrator access to Docker Home and your identity provider
How group mapping works
Group mapping uses IdP attributes to keep Docker Team membership synchronized:
- With SAML SSO, the IdP sends group membership when a user signs in.
- With SCIM, the IdP synchronizes group membership on its provisioning schedule.
- Docker identifies users by email address. Each Docker account must have a unique email address.
- Docker creates teams when a mapped group references a team that doesn't exist.
Set up group mapping
To configure group mapping:
- Create groups in your IdP using Docker's naming format
- Configure your IdP to send group data
- Add users to the groups
- Test that membership synchronizes
You can use group mapping with SAML SSO alone or with SCIM for user lifecycle management.
Group naming format
Create groups in your IdP using the format: organization:team.
For example:
- For the "developers" team in the "moby" organization:
moby:developers - For multi-organization access:
moby:backendandwhale:desktop
Docker creates teams automatically if they don't already exist when groups sync.
Supported attributes
| Attribute | Description |
|---|---|
id | Unique ID of the group in UUID format. This attribute is read-only. |
displayName | Group name in the organization:team format. |
members | A list of users that are members of this group. |
members(x).value | Unique ID of a user in the group. |
Configure group mapping with SSO
Use group mapping with SSO connections that use the SAML authentication method.
NoteGroup mapping through SSO isn't supported with the Microsoft Entra ID OIDC authentication method. Use SCIM to synchronize groups for OIDC connections.
The IdP interface may differ from these steps. For more information, see the Okta documentation.
To set up group mapping:
- Sign in to Okta and open your application.
- Navigate to the SAML Settings page for your application.
- In Group Attribute Statements (optional), configure these values:
- Name:
groups - Name format:
Unspecified - Filter: Starts with and
organization:, whereorganizationis your Docker organization name
- Name:
- Create your groups by selecting Directory, then Groups.
- Add groups in the
organization:teamformat that match your Docker organization and team names. - Assign users to the groups.
The next time users sign in, Docker maps them to the teams you defined.
The IdP interface may differ from these steps. For more information, see the Microsoft Entra ID documentation.
To set up group mapping:
- Sign in to Entra ID and open your application.
- Select Manage, then Single sign-on.
- Select Add a group claim.
- In Group Claims, select Groups assigned to the application with the source attribute Cloud-only group display names.
- Select Advanced options, then the Filter groups option.
- Configure the attribute like the following:
- Attribute to match:
Display name - Match with:
Contains - String:
:
- Attribute to match:
- Select Save.
- Select Groups > All groups > New group to create your groups.
- Assign users to the groups.
The next time users sign in, Docker maps them to the teams you defined.
Configure group mapping with SCIM
Use group mapping with SCIM to synchronize membership on your IdP's provisioning schedule. Before you begin, set up SCIM.
The IdP interface may differ from these steps. For more information, see the Okta documentation.
To set up your groups:
- Sign in to Okta and open your application.
- Select Applications, then Provisioning, and Integration.
- Select Edit, enable Push Groups, then select Save. The Push Groups tab appears in your application.
- Create your groups by navigating to Directory and selecting Groups.
- Add groups in the
organization:teamformat that match your Docker organization and team names. - Assign users to the groups.
- Return to Integration, then select Push Groups.
- Select Push Groups, then Find groups by rule.
- Configure the groups by rule like the following:
- Enter a rule name, such as
Sync groups with Docker. - Match groups by name. For example, use Starts with and
moby:, or Contains and:for multiple organizations. - To sync after changes to groups or assignments, enable Immediately push groups by rule.
- Enter a rule name, such as
Find the rule under By rule in the Pushed Groups column. Matching groups appear in the groups table.
To push the groups from this table:
- Select Group in Okta.
- Select the Push Status drop-down.
- Select Push Now.
The IdP interface may differ from these steps. For more information, see the Microsoft Entra ID documentation.
- Sign in to Entra ID and go to your application.
- In your application, select Provisioning, then Mappings.
- Select Provision Microsoft Entra ID Groups.
- Set Enabled to Yes.
- Confirm these attribute mappings:
displayNametodisplayNameobjectIdtoexternalIdmemberstomembers
- Select Save.
Next, set up group mapping:
- Go to Users and groups.
- Select Add user/group.
- Select groups that use the
organization:teamformat. - Select Assign.
- Go to Provisioning and select Start provisioning.
To verify the sync, select Monitor, then Provisioning logs. In Docker Home, confirm that members appear in the mapped teams.
After synchronization, Docker adds users to the organizations and teams mapped in the IdP.
TipEnable SCIM to provision and deprovision users automatically. Group mapping through SSO manages team membership but doesn't deprovision users.
Next steps
- Assign roles to organization members.
- Enforce sign-in for your organization.