<div dir="ltr">We've got a class of users that are allowed access to a limited set of SPs.<div>These users are our legacy SSO guest accounts, and we only allow them to access local resources where the resource owner requests it.</div><div><br></div><div>In IdP 2.x, we created a module for uApprove that checks to see if the user is a guest, and if they're accessing one of the pre-approved SPs.  If they are a guest and accessing an SP that isn't on the list, they're denied.</div><div><br></div><div>I'm trying to figure out how to replicate this with an intercept flow.  The example intercept flow allows access to users with an ePPN trying to access a specific SP.</div><div><br></div><div>I need something that denies access to users with a specific attribute value, unless they're trying to access an SP that's on the list.</div><div><br></div><div>Any help would be appricated</div><div><br></div><div>thanks!</div><div>Liam</div></div>