<div dir="ltr">The times we've had to do that, we do it by denying all attribute release.<div>Most SPs will require you to send them /something/</div><div><br></div><div>Liam</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Feb 13, 2017 at 3:13 PM, Patrick Rynhart <span dir="ltr"><<a href="mailto:P.Rynhart@massey.ac.nz" target="_blank">P.Rynhart@massey.ac.nz</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi all,<br>
<br>
We've got a Service Provider that is currently available to all members of our organisation, but we want to restrict it to only members of a particular LDAP group.  We have tried working with the provider, but they don't support an attribute that could be disallow access at there end.<br>
<br>
Is there anyway that we can "block" access from our end (i.e. the IdP) ?  If so, how do we go about it ?<br>
<br>
With Thanks in Advance<br>
<br>
Patrick Rynhart<br>
<br>
-----<br>
<br>
Patrick Rynhart | Systems Engineer (Technical Applications)<br>
Information Technology Services, Massey University<br>
Private Bag 11-222, Palmerston North 4442, New Zealand<br>
Ph <a href="tel:%2B64%206%20356%209099%20extn%2083605" value="+6463569099" target="_blank">+64 6 356 9099 extn 83605</a>|Email <a href="mailto:p.rynhart@massey.ac.nz" target="_blank">p.rynhart@massey.ac.nz</a><span class="HOEnZb"><font color="#888888"><br>
<br>
-- <br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</font></span></blockquote></div><br></div>