Automate adding users to a security group

Hi guys,

With SAML configured we have a situation when before adding a user to a new group new users have to login to the portal once, so their account would appear in the database.
So if we add a new Team with 10 users I first would need to ask then to login once, then I could find them all in the list and update the membership.
This is not very convenient of course.
Can you suggest a better way to authenticate against AAD and automate the process?


Hey there.

Have you considered also syncing groups to SonarQube (see the documentation on Group Mapping). This means that as long as a group is created in SonarQube that matches a group being sent by your authentication provider, a user will be added to the necessary groups when logging in for the first time.

Sorry for the delay Colin. Was waiting for our infra guys.
So I have a group configured in SonarQube.
I have the same group configured in AD (which is our IP. Sorry for confusion above).
I added myself to the group in AD and on SQ portal.
After first login I see myself a part of Users grp only.

SAML group attribute ( is configured with “

If I reset this record my users keep manually assigned groups.
But as you can see above, with this feature configured my users lose all their groups.

Please advise on how I can troubleshoot this.


Also FYI, we gave the following ADFS settings:

AllowedAuthenticationClassReferences : {}
EncryptionCertificateRevocationCheck : CheckChainExcludeRoot
PublishedThroughProxy : False
SigningCertificateRevocationCheck : CheckChainExcludeRoot
WSFedEndpoint :
AdditionalWSFedEndpoint : {}
ClaimsProviderName : {Active Directory}
ClaimsAccepted : {}
EncryptClaims : True
Enabled : True
EncryptionCertificate :
Identifier : {XXX}
NotBeforeSkew : 0
EnableJWT : False
AlwaysRequireAuthentication : False
Notes :
OrganizationInfo :
ObjectIdentifier : c-8
ProxyEndpointMappings : {}
ProxyTrustedEndpoints : {}
ProtocolProfile : WsFed-SAML
RequestSigningCertificate : {}
EncryptedNameIdRequired : False
SignedSamlRequestsRequired : False
SamlEndpoints : {Microsoft.IdentityServer.Management.Resources.SamlEndpoint}
SamlResponseSignature : AssertionOnly
SignatureAlgorithm :
TokenLifetime : 0
AllowedClientTypes : Public
IssueOAuthRefreshTokensTo : NoDevice
RefreshTokenProtectionEnabled : True
RequestMFAFromClaimsProviders : False
ScopeGroupId :
Name : XXX
AutoUpdateEnabled : False
MonitoringEnabled : False
MetadataUrl :
ConflictWithPublishedPolicy : False
IssuanceAuthorizationRules : @RuleTemplate = “AllowAllAuthzRule”
=> issue(Type = “”, Value = “true”);

IssuanceTransformRules : @RuleTemplate = “LdapClaims”
@RuleName = “SonarQube Userclaims”
c:[Type == “”, Issuer == “AD AUTHORITY”]
=> issue(store = “Active Directory”, types = (“”,”,”,”, “”), query =
“;userPrincipalName,displayName,mail,sAMAccountName,tokenGroups;{0}”, param = c.Value);

DelegationAuthorizationRules :
LastPublishedPolicyCheckSuccessful :
LastUpdateTime : 1/1/1900 1:00:00 AM
LastMonitoredTime : 1/1/1900 1:00:00 AM
ImpersonationAuthorizationRules :
AdditionalAuthenticationRules :
AccessControlPolicyName :
AccessControlPolicyParameters :
ResultantPolicy :

Could you specify the parameter that has to be modified?