Updated the single sign-on settings page and included a new section for role mapping. If '''Role Mapping''' is set to''' Enabled''', users will be provisioned with all the roles as defined by the assertion attributes and they will be stripped of any roles that they may currently possess that are listed in this setting but were not defined in the assertion attributes. Updates were made to labels, tooltips, and title bars for added clarity.
<!-- 124791 - SSO to update roles for existing users for a fully federated SSO -->
[[File:2022-07-ticket-124791-1.png|thumb|none|800px|Caption]]
====Updated Behavior to User/Organization Security Matrix====