Original Message:
Sent: Thu June 22, 2023 07:16 AM
From: srinivasa kalyana chakravarthy
Subject: ISVA - custom identity mapping rule to restrict user access.
Thanks Jack for the suggestion.I will try this too and get back.
------------------------------
srinivasa kalyana chakravarthy
Original Message:
Sent: Wed June 21, 2023 10:59 AM
From: JACK YARBOROUGH
Subject: ISVA - custom identity mapping rule to restrict user access.
Using an Access Policy is also preferable because it won't interrupt the SAML SSO flow and can be customized on a per-partner basis.
This means you can use the same Identity Mapping just for the attributes and leave the access logic to the Access Policy.
Here is our documented example for Group based logic:
https://www.ibm.com/docs/en/sva/10.0.2?topic=policies-sample-file-access
It specifically has a group membership example.
You can also have more flexibility on the page you return or the action you take when the user is denied access.
------------------------------
JACK YARBOROUGH
Original Message:
Sent: Tue June 20, 2023 09:00 AM
From: srinivasa kalyana chakravarthy
Subject: ISVA - custom identity mapping rule to restrict user access.
Hi All
I am working on the identity mapping rules of SAML in ISAM 10.0.2.
I have a requirement to check if a user is a member of certain LDAP groups and then allow access to the Service Provider.
I am able to retrieve the groups that a user is member of but I am unable to deny access if a user isn't a member of the LDAP groups.
Any help would be highly appreciated.
Thanks,
Kalyan
------------------------------
kalyan
------------------------------