After configuring SAML authentication for Strategy Web or Strategy Mobile, attempting to access the Web or Mobile Admin page results in a 403 error.
This is because the Admin Groups in SAML configuration not correctly defined.
Open SAML configuration page with below URL:
<application_path>/saml/config/open

NOTE: Some IDPs may have a configurable filter that determines which group information is sent. Instead of sending over all groups that a user belongs to, make sure the desired group information is sent to Strategy.