Legacy Knowledge Base
Published Sep. 10, 2025

How to map Liferay site roles with Azure AD

Written By

Rishabh Agrawal

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • How to map Liferay site roles to Azure AD roles when configuring SAML?
  • For example, if there is a role called Content Author under site roles, how to configure this role in Azure AD?

Environment

  • Liferay DXP [all versions]

Resolution

  1. As per the compatibility matrix, Liferay DXP Self hosted Integrated Technologies Compatibility Matrix, Microsoft Azure is not supported as an Identity Provider (IdP), therefore, the support provided with this current integration is limited.
  2. The supported IdPs are ADFS, Liferay DXP, Liferay Portal EE, Okta, OpenAM 13+, PingFederate, Shibboleth, and Siteminder.
  3. However, direct role mapping between Liferay site roles and Azure AD roles is not supported when using SAML.
  4. Users can achieve similar functionality by mapping Azure AD groups to Liferay user groups and then assigning these groups to site roles.

Additional Information

Did this article resolve your issue ?

Legacy Knowledge Base