<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div>Hi,</div>
<div><br>
</div>
<div>We are working with one of the vendor that asking us to send the SAML Response message with Status Code as &nbsp;'<font face="tahoma, sans-serif">urn:oasis:names:tc:SAML:2.0:status:RequestDenied’&nbsp;</font></div>
<div><font face="tahoma, sans-serif"><br>
</font></div>
<div><span style="font-family: tahoma, sans-serif;">Is there any way to set the status code to RequestDenied&nbsp;</span><font face="tahoma, sans-serif">if certain attribute of the users doesn’t meet the requirement?&nbsp;</font></div>
<div><font face="tahoma, sans-serif"><br>
</font></div>
<div><font face="tahoma, sans-serif">The attribute-filter rule still set the status code as&nbsp;’Success' with Empty attributes to SP&nbsp;</font><span style="font-family: tahoma, sans-serif;">if user attribute doesn’t meet the filter rule.</span></div>
<div><font face="tahoma, sans-serif"><br>
</font></div>
<div><font face="tahoma, sans-serif">Thank you so much for your help,</font></div>
<div><font face="tahoma, sans-serif">Nat</font></div>
</body>
</html>