releasing AD group names

IAM David Bantz dabantz at
Fri Apr 8 21:30:22 UTC 2022

That’s the reasonable behavior I anticipated, but the service is not
protected by Shibboleth SP and they are adamant that no mapping or
transformation of SAML attribute values is possible.

On 08Apr2022 at 13:25:24, Bruce Timberlake via users <users at>

> That seems like something the SP should be able to do if they can't
> consume the attributes as they are natively released...
> comes to mind?
> Caveat - I am replying more on my understanding of how it should work than
> on actual implementation experience/knowledge :)
> --
> *Bruce Timberlake*
> *Sr Application Systems Administrator*, Identity and Access Management
> Services
> ITS - Information Assurance
> University of Michigan
> --
> For Consortium Member technical support, see
> To unsubscribe from this list send an email to
> users-unsubscribe at
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the users mailing list