We have a service provider that is using federation metadata in it's MetadataProvider definition. As a result, we can craft login urls for any IdP included in the metadata used by that SP, and it will let those users in.<div>
<br></div><div>I know we could use the RequestMap to deny access based on attribute values. </div><div><br></div><div>Short of ditching the federation metadata, and configuring MetadataProviders for the specific IdPs we want to talk to, is there a way to limit which IdPs it will permit authentication from? Can will filter out the unwanted IdPs somehow?</div>
<div><br></div><div>Liam</div><div><br></div><div><br></div>