<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, May 25, 2017 at 2:23 PM, IAM David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Is it feasible in IdP 3.3 to intercept an authN failure against AD LDAP due to expired account (error 49, data 701) and treat as though successful authN? ("701" data is supposed to be returned ONLY if the supplied credentials were otherwise valid, so this does not bypass expired password, locked account, or bad password, but only those attempts that would have been successful but for the account being marked expired.)</div></div></blockquote><div><br></div><div>So do you want to ignore this particular account state or will you be sending these users somewhere to unexpire their account in a self-service fashion?</div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div></div>