<div dir="ltr">One of our units on campus has set up their instance of NetIQ Access Manager to proxy authn requests to our IDP (Access Manager would normally be an IDP).<div><br></div><div>Apparently, Access Manager has a concept of "defederation":</div><div><br></div><div>    If you have configured the Identity Server to be a service provider</div><div>    and have established a trusted relationship with one or more identity</div><div>    providers, the cards of these trusted identity providers appear in the</div><div>    Authentication Cards section. Your users can use the identity provider’s</div><div>    authentication card to federate their account at the identity provider with</div><div>    their account at the service provider. When they federate an account, they</div><div>    are telling the service provider to trust the authentication established at the</div><div>    identity provider. This enables single sign-on between the providers. The</div><div>    card can also be used to defederate the accounts. On the authentication card,</div><div>    click Card Options, then select Defederate.<br></div><div><br></div><div>The team running this server expects the act of "defederation" in thier application to contact the our IDP and expire the given user's persistent ID.</div><div><br></div><div>The feels awfully vendor specific.  Is this a standard SAML thing?</div><div><br></div><div>Liam</div></div>