<div dir="ltr"><div><div>Hi folks,<br><br></div>does the IdP provide functionality to allow/deny a user based on LDAP attributes for a certain SP?<br></div><div>In our federation are SPs which can cause costs. We want to avoid that particular users can access those services. Because these services are not maintained by our organization, we want to make the decision on the side of the IdP. <br><br>Best regards,<br></div><div>Larissa<br></div></div>