You need to designate an appropriate custom principal via the DefaultRelyingParty by setting the applicable profile beans' defaultAuthenticationMethods property, with some additional protections to block overriding it. e.g. https://wiki.shibboleth.net/confluence/display/IDP30/SAML2SSOConfiguration Examples of defaultAuthenticationMethods property -- Scott