Hi MK,
Just to clarify... are you trying to perform this group check on Identity Provider or on Service Provider?
Is the Active Directory you want to read groups from a "federated directory" in your Access Manager system or is it totally independent?
Perhaps you could provide a little more information on the flow of user data through the federation so we can understand the requirement better.
Inside the JavaScript you use to write an Access Policy, you do have access to a Helper class (LDAP Lookup Helper) but based on other appends on this forum, I think this really only works if the Active Directory is federated into Access Manager (others can comment on this).
There is a more generic Helper in the latest product version (Verify Access v10) but I think there have been some challenges here related to class whitelisting (others can comment if those have been fixed yet). What version are you using?
Anyway, please give us a little more detail and the community will try to assist you with the best approach.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------
Original Message:
Sent: Wed July 22, 2020 06:54 AM
From: Madhu Kolli
Subject: isam access policy with AD group info
Howdy everyone,
We have a requirement where we need to write a access policy that should get group info from AD and verify it. This policy will be attached to SAML partner to prevent unauthorized access (who ever is not in that AD group) DId anyone had worked on a requirement like this one before. Looking for sample code or a way to do it (how can we make connection to AD since we cant use stsuu). Appreciate it in advance.
Thanks
MK
------------------------------
MK
------------------------------