Thanks Scott, Is the SP granting access because of NotOnOrAfter still present in the SAML response? What kind of enforcement/check this PolicyRule makes in SP? <PolicyRule type="Conditions"> <PolicyRule type="Audience"/> </PolicyRule>