<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Dec 28, 2016 at 11:43 AM, O'Dowd, Josh <span dir="ltr"><<a href="mailto:Josh.O'Dowd@mso.umt.edu" target="_blank">Josh.O'Dowd@mso.umt.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I think we just need some advice on how to implement our policy where expired, expiring, or reset password conditions occur.  Again, we just want to sub-flow these so that we can get password renewed, and then send user on their way to their requested service.</blockquote></div><br>That seems to my perhaps naive eyes to be building a lot of customization into the Identity Provider to have it act as a credential manager. We use an alternative strategy of referring any "help with credentials" issue to a separate service dedicated to helping folks maintain directory-based credentials. Just offering a different perspective.</div><div class="gmail_extra"><br></div><div class="gmail_extra">David Bantz</div><div class="gmail_extra">UA OIT IAM</div></div>