Finding the group ID for SAML group matching
Enable and configure SAML group matching if you only want to allow Azure Active Directory (AD) users of a certain group to authenticate. Otherwise, leave this setting disabled. You can further define more granular groups when you configure user group settings.
To find the Azure AD Group ObjectId in Azure AD:
- In the left pane of the Azure portal (three horizontal lines), select Azure Active Directory. Under Manage, select Groups.
- The default view shows all groups. Find the desired group and note the Object Id.
For details on creating a new security group, see Create a security group for the test user in Tutorial: Azure AD SSO Integration with FortiGate SSL VPN.
You can find the full list of group claims in Configure group claims for applications with Azure Active Directory.
Read more here: Source link
