We have followed these instructions:
Error message in web gui is :
Sorry, you are not allowed to access Lenses. Please contact your admin.
We can see from debug logs in Lenses that Azure AD groups are populated to Lenses at login attempt.
Somehow the mapping between the azure AD groups and Lenses group fails.
2023-01-24 08:43:06,347 DEBUG [o.a.x.s.u.DigesterOutputStream] <Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion".....
<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/groups"><AttributeValue>fb7c6305-25a1-46ff-919a-307dd8ddb6fd</