diff --git a/controllers/drupalsite_resources.go b/controllers/drupalsite_resources.go
index 317f73bf45468dd4a0dcabf687864219ba0d744d..af6b45fbedc91d154e8accc20da58aa450d8a134 100644
--- a/controllers/drupalsite_resources.go
+++ b/controllers/drupalsite_resources.go
@@ -1029,6 +1029,14 @@ func deploymentForDrupalSite(currentobject *appsv1.Deployment, databaseSecret st
 						Name:  "OAUTH2_PROXY_SKIP_AUTH_REGEX",
 						Value: "_webdav",
 					},
+					{
+						Name:  "OAUTH2_PROXY_OIDC_GROUPS_CLAIM",
+						Value: "cern_roles",
+					},
+					{
+						Name:  "OAUTH2_PROXY_ALLOWED_GROUPS",
+						Value: "cern_registered",
+					},
 					{
 						Name:  "OAUTH2_PROXY_PROVIDER",
 						Value: "oidc",
@@ -1225,6 +1233,14 @@ func deploymentForDrupalSite(currentobject *appsv1.Deployment, databaseSecret st
 					Name:  "OAUTH2_PROXY_SKIP_AUTH_REGEX",
 					Value: "_webdav",
 				},
+				{
+					Name:  "OAUTH2_PROXY_OIDC_GROUPS_CLAIM",
+					Value: "cern_roles",
+				},
+				{
+					Name:  "OAUTH2_PROXY_ALLOWED_GROUPS",
+					Value: "cern_registered",
+				},
 				{
 					Name:  "OAUTH2_PROXY_PROVIDER",
 					Value: "oidc",