If you want to use Active Directory groups for restrictions in Cameyo, you have to configure group claims in your Entra ID SSO app. 

Unfortunately Microsoft Entry ID only supports sAMAccountNames when it is connected to an on-prem Active Directory using Entry Connect. If you are using a pure Entra ID directory, only the group IDs are delivered!


Follow these steps to configure group claims:


  1. Log in to your Azure portal
    https://portal.azure.com

  2. Open your Entry ID

  3. Navigate to [App Registrations]

  4. Open the Cameyo SSO app (The name can vary)
  5. Navigate to [Token configuration]

  6. Click [Add groups claim]

  7. Select all group types

  8. Expand all token and select [sAMAccountName] for ID, Access and SAML

  9. Click [Add]

  10. In order to synchronize groups with Cameyo, enter groups into the [SSO claim for groups] field on the company page:

Be aware that only groups of users that log in to Cameyo will be synchronized and that you need to wait a few minutes until the groups are visible under restrictions.