basically in cloud IMS groups does not work on publish environment , we have to create seperate groups in AEM publish and provide permission .Also when user is logged in through SAML , it got created under /idp folder and all the groups that are the part of saml response with attribute as groupmembe...