IdP v3 preventing some accounts

Richard Frovarp richard.frovarp at ndsu.edu
Mon Jun 20 17:36:56 EDT 2016


I'm doing AD / LDAP authentication using the built in method. What I 
need to do is prevent some accounts from logging in / being passed on to 
the SP. These account may be shared accounts that we haven't been able 
to kill off and/or guest accounts that we don't want to expose to the 
federation. These accounts are in the same OU as the rest of our 
accounts, so I can't do OU filtering.

What's the best method of filtering either the good or bad accounts? I 
don't see anything obvious to go against a group, but I may be missing 
it. Or do I go down the MCB path?

Thanks,
Richard


More information about the users mailing list