@kolluax Normally how it works is the users who wants to login to AEM Author has to apply for access roles(Author, Approver, Admin) within the organization and get the approval for the roles and that group information will be stored in either LDAP/Active Directory. When the IDP (like Salesforce or ...