SAML Authentication - App creation restrictions using "groups"


I would like to restrict app creation to certain user group
this is the SAML assertion sent from the IDP to dash:

<saml:Attribute FriendlyName=“groups” Name=“groups” NameFormat=“urn:oasis:names:tc:SAML:2.0:attrname-format:uri”>
<saml:AttributeValue xmlns:xsi=“” xsi:type=“xs:string”>RestrictedCreationGroup</saml:AttributeValue></saml:Attribute>

Dash doesn’t read the groups and still prevent users from creating new app.

What am I missing?