Game on: New releases
1783477859582
Associated Users: One user, multiple groups.
Managing users who belong to multiple teams or departments just got a lot simpler.
Get greater flexibility when managing users synced from identity providers, without creating duplicate users or compromising policy assignments. With Associated Users, Scalefusion now supports associating a single user with multiple user groups while maintaining one Primary group membership.
Here's what's new:
Associate users with multiple groups
Users can now have one Primary group and be associated with multiple additional groups. You can also manually add associated users from the Associated Users tab within a User Group.
Automatic IdP group associations
When user groups are imported from your Identity Provider, Scalefusion automatically assigns a user as Primary in one group and marks them as an Associated User in every other imported group they belong to.
Predictable policy assignment
Device Profiles and application assignments continue to be determined by the user's Primary group, ensuring existing policy behavior remains consistent.
SSO assignments now recognize associated users
When a User Group is assigned to or exempted from an SSO application, the configuration automatically applies to all users in that group—including associated users.
Enhanced SCIM group mapping
SCIM integrations now send all group memberships for a user, including both Primary and Associated groups, to the target application for more accurate provisioning.
Swap Primary membership with ease
Need to change a user's Primary group? Use the new Swap option to promote any associated group as the Primary group while automatically updating the remaining memberships. This is especially useful for users imported from an IdP who belong to multiple groups.
Conditional SAML Attributes: More control over what your apps receive
SAML attribute mapping is now more flexible with support for conditional attribute configuration.
Now configure SAML attributes based on a user's group membership, making it easier to deliver the right identity information to different applications without creating separate SSO configurations.
You can now choose to:
Send an attribute only for selected groups: Configure an attribute to be included only when the user belongs to one or more specified User Groups.
Send an alternate attribute value: Define a different value for an existing attribute when users belong to selected User Groups, enabling group-specific access and application behavior.
Obtain finer control over SAML assertions while simplifying identity management for users across different teams and organizational structures.
macOS MDM Agent: Improved Secure Web Gateway reliability
We’ve fixed performance degradation and intermittent connectivity issues that could occur when Secure Web Gateway policies were applied, resulting in a more reliable browsing and network experience for managed macOS devices.
Did you like this update?
![]()
![]()
![]()
Leave your name and email so that we can reply to you (both fields are optional):
