Category filter

Assign Users/Groups to Applications for Enterprise Single Sign-On

In Hexnode IdP, you can manage access to your enterprise applications by assigning users and groups directly to them. This ensures that only authorized identities can access your organization’s tools and data. You can control access by assigning users or user groups directly to individual applications (SAML 2.0 or OIDC), or you can streamline access management by assigning them to app groups.
This article guides you through assigning and unassigning user or group access to applications and app groups.

Prerequisites

Before assigning access, ensure that:

  • You are logged in to the Hexnode IDP portal as an administrator.
  • The application (SAML 2.0 or OIDC) has been configured and added under Applications > MyApps, or an App Group has been created under Applications > App Groups.

Assign access to an individual application

Follow these steps to grant or deny access to a single application in your directory.

  1. Log in to the Hexnode IDP portal.
  2. Navigate to Applications > MyApps.
  3. Select the application you want to manage and navigate to the Assignments section.
  4. On the left side of the screen, choose the category of identities you want to view: All, Users, or Groups.
  5. Screenshot of the Hexnode IDP portal showing the MyApps section under the Applications tab. A specific application is selected, displaying the Assignments section used to Assign Users to Applications, with options on the left-hand side to view identity categories such as All, Users, or Groups.

  6. From any of these tabs, you can choose to Include or Exclude specific users or groups by clicking the Add button.
    1. Include grants access to the application.
    2. Exclude prevents access, even if the user is part of an included group.
  7. Once you have completed the assignments, click on Save.
Note:


The Exclude assignment strictly overrides the Include assignment. If a user/group is added to the Excluded tab, they are explicitly denied access to the application, regardless of whether they belong to a user/group that is currently Included tab.

Unassign users or groups from an application

If a user or group no longer requires access, or if an exclusion rule needs to be lifted, you can remove their assignment.

  1. Log in to the Hexnode IDP portal.
  2. Navigate to Applications > MyApps.
  3. Select the application you want to manage and navigate to the Assignments section.
  4. On the left side, choose the category of identities you want to view: All, Users, or Groups.
  5. Select the Included or Excluded tab where the user or group is currently assigned.
  6. Select the specific users or groups you want to unassign.
  7. Click the Remove (x) option to remove the assignment.

Assign access using App Groups

As your organization grows, managing access to each application individually can become difficult. App Groups allow administrators to bundle previously integrated applications based on teams, roles, or business functions, and assign access to all of them in a single action.

  1. Log in to the Hexnode IDP portal.
  2. Navigate to Applications > App Groups.
  3. Select an existing App Group from the list.
  4. Navigate to the Assignments section.
  5. On the left side, choose the category of identities you want to view: All, Users, or Groups.
  6. From any of these tabs, you can choose to Include or Exclude specific users or groups by clicking the Add button.
    1. Include grants access to the application.
    2. Exclude prevents access, even if the user is part of an included group.
  7. Once you have completed the assignments, click on Confirm.
Note:


Similar to individual applications, Exclude prevents access and takes precedence even if the user is a member of an included group.

Unassign users or groups from an App Group

To remove bulk access granted via an App Group:

  1. Log in to the Hexnode IDP portal.
  2. Navigate to Applications > App Groups.
  3. Select the existing App Group you want to manage and navigate to the Assignments section.
  4. On the left side, choose the category of identities you want to view: All, Users, or Groups.
  5. Select the Included or Excluded tab where the user or group is currently assigned.
  6. Select the specific users or groups you want to unassign.
  7. Click the Remove (x) option to clear their assignment from the App Group.

Screenshot of the Hexnode IDP portal showing the App Groups section under the Applications tab. An existing App Group is selected, displaying the Assignments section used to unassign or Assign Users to Applications, with the left-hand menu offering options to view identity categories including All, Users, or Groups. Specific users or groups from the list are selected, and the Remove (x) option is clicked to remove the assignment.

Frequently Asked Questions

How do you create an App Group in Hexnode IDP?

Creating an App Group involves initializing the group and then adding your configured applications to it:

  1. Log in to the Hexnode IDP portal and navigate to Applications > App Groups.
  2. Click Add App Group.
  3. Click the edit icon next to Untitled App Group to provide a meaningful name, optionally add a description, and click Save.
  4. In the Apps section, click the Add Apps button to display a list of all integrated applications.
  5. Select the applications you wish to include, click Confirm to bundle them, and click Next to proceed to the assignment phase.
Can you add both SAML 2.0 and OIDC applications to the same app group in Hexnode IDP?

Yes. App Groups can contain any applications that have already been configured and integrated into Hexnode IDP, including both SAML 2.0 and OIDC applications. There are no restrictions on mixing different authentication protocols within the same group.

Apps