<div dir="ltr"><div>Hi:</div><div><br></div><div>I have configured shibboleth SP(Ver 2.5.3) to work with the two IdPs (OKTA1 & OKTA2). </div><div><br></div><div>   <MetadataProvider type="Chaining"></div><div>      <MetadataProvider type="XML" file="/etc/shibboleth/Okta1.xml"/></div><div>      <MetadataProvider type="XML" file="/etc/shibboleth/Okta2.xml"/></div><div>   </MetadataProvider></div><div><br></div><div>I am getting the Email, UserName, FirstName, & LastName as attributes from IdP.</div><div><br></div><div>I want to enforce a rule in such a way that the email address of the users authenticated through OKTA1 must have @<a href="http://abc.com">abc.com</a> as their domain address and OKTA2 users must have @<a href="http://xyz.com">xyz.com</a> as the domain address.</div><div><br></div><div>Is it possible to enforce this rule? If the email attribute does not follow the rule, can we reject the incoming request?</div><div><br></div><div>If yes, can you please give me some documentation or example on how to proceed on this?</div><div><br></div><div>Thanks</div><div><br></div><div>Nara</div><div><br></div></div>