> Is this broadly how it works? or is there any other configuration files that > need to be configured as well in order to make this attribute-release process > works? You have a lot less to configure if you reuse standard attributes already defined in LDAP (and thus SAML) and provided in example configuration. That's about all I would add. -- Scott