Hello, 
I implemented Cyberark integration in OpenStack. I used the SAML protocol during the integration. I created user groups in Active Directory and defined these groups in Openstack. I added users to the created groups. My goal is to send requests to the OpenStack API by creating application credentials. However, the federated user added to the groups created as a result of the Cyberark integration cannot create and use application credentials.
 
It gives the following error: 

Unable to create application credential. 

Inventory
openstack:stein 
keystone: 15.0.1-0ubuntu1~cloud0 

 Can you help me solve this problem?

Thanks