# Jenkins does not process AD groups via SAML Plugin

**URL:** <https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187>\
**Category:** Using Jenkins\
**Tags:** question\
**Created:** [September 6, 2024, 7:41am UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187 "2024-09-06T07:41:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukas](https://avatars.discourse-cdn.com/v4/letter/l/e9a140/32.png) [@lukas](https://community.jenkins.io/u/lukas)\
**Post date:** [September 6, 2024, 7:41am UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187/1 "2024-09-06T07:41:31Z")

</div>

Hi,  
i have the following problem:  
We’re using the SAML Plugin to login users via SSO. The SSO Token is correct and provides AD groups, UserID, username and so on. It works fine for our team members, which are assigned to a global admin role.  
For other users this does not work. When they click on their profile, there are no groups listed, and they can’t see anything in Jenkins. Their User-ID and username, provided via SAML, are displayed correctly though. The groups are correctly displayed when i look at https://.com/user/  
We’re using Role Based authorization, with Global and Item roles. These roles are assigned to the active directory groups in Jenkins.  
I hope anybody has an idea to help with this issue.

Jenkins Version: 2.462.1  
SAML Plugin Version: 4.464.vea\_cb\_75d7f5e0 ([SAML](https://plugins.jenkins.io/saml))

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [September 10, 2024, 9:37am UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187/2 "2024-09-10T09:37:51Z")

</div>

Hello @lukas,

Could it be that your SAML groups aren’t correctly mapped to the Jenkins roles for non-admin users?

---

<div class="post-metadata">

**Author:** ![lukas](https://avatars.discourse-cdn.com/v4/letter/l/e9a140/32.png) [@lukas](https://community.jenkins.io/u/lukas)\
**Post date:** [September 12, 2024, 11:28am UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187/3 "2024-09-12T11:28:04Z")

</div>

The roles should be mapped correctly. I have assigned myself a developer group, and it is displayed in my Jenkins user profile. The same group is not shown, when a developer opens his profile.

---

<div class="post-metadata">

**Author:** ![tmorgan](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@tmorgan](https://community.jenkins.io/u/tmorgan)\
**Post date:** [June 2, 2025, 6:37pm UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187/4 "2025-06-02T18:37:22Z")

</div>

Ran into a simlar issue. Ours turned out to be the groups were being returned from SAML as the full DN. If you have a similar issue, go check an example user and see what groups are being returned by your SAML provider and make sure your Jenkins groups match verbatim.

Side note, from what I see on our deployments, users can’t see their groups in Jenkins, only the admins can see the users groups.

---

<div class="post-metadata">

**Author:** ![mawinter69](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/mawinter69/32/1625_2.png) [@mawinter69](https://community.jenkins.io/u/mawinter69)\
**Post date:** [June 2, 2025, 7:50pm UTC](https://community.jenkins.io/t/jenkins-does-not-process-ad-groups-via-saml-plugin/19187/5 "2025-06-02T19:50:14Z")

</div>

Going to `/whoAmI` shows the authorities (groups) for the logged in user also for non admins.
