<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small">Hello Joanne,</div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small">It sounds like what you need is a <a href="https://wiki.shibboleth.net/confluence/display/IDP30/ContextCheckInterceptConfiguration">"context-check" interceptor flow</a>. With this flow, you can interrupt the authentication process and have the IdP look at the SP being requested and then at some user attribute(s) to decide whether to halt the flow or let it continue. We use this for controlling access to one of our SPs and it has made life a whole lot easier.</div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small">Hope that helps!</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><font face="arial, helvetica, sans-serif"><br>Brian Moon<br><font size="1">Senior System Administrator, Enterprise Systems</font></font></div><div dir="ltr"><font size="1"><font face="arial, helvetica, sans-serif">Santa Clara University</font></font><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jul 15, 2020 at 11:02 AM Schwendner, Joanne <<a href="mailto:joanne_schwendner@brown.edu">joanne_schwendner@brown.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Does anyone have experience with controlling access to individual Organizations in GitHub Cloud? We would like to control access by using Grouper group memberships. We are successfully using their SAML SSO support. But... <div><div><br><div>It seems the only attribute GitHub cares about is NameID. We are currently passing our persistent ID in NameID. If it's there, they get in. To block access for a user, we would have to NOT send NameID in the assertion, if that's even possible.<input name="virtru-metadata" type="hidden" value="{"email-policy":{"state":"closed","expirationUnit":"days","disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"persistentProtection":false,"expandedWatermarking":false,"expires":false,"isManaged":false},"attachments":{},"compose-id":"9","compose-window":{"secure":false}}"></div><div><br></div><div>Is it possible to conditionally NOT send NameID depending on a user's other attributes? Is there another way to manage GitHub Org access (besides manually)?</div><div><br></div></div><div>Thanks.</div><div>Joanne</div><div><br></div><div>---</div><div><br></div><div><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Joanne Schwendner</span><br style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif"><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Senior Developer - </span><font color="#888888">Web, Integration, & Identity Services</font><br style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif"><span style="color:rgb(32,33,36);font-family:arial,helvetica,sans-serif">Brown University</span> </div><div> <br></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!MLMg-p0Z!TkYOp7DK4febwUmzMBSD_h1dI7wP0QRmasfVrmAe3f2AzBUVX9rwc26wmlpY$" rel="noreferrer" target="_blank">https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!MLMg-p0Z!TkYOp7DK4febwUmzMBSD_h1dI7wP0QRmasfVrmAe3f2AzBUVX9rwc26wmlpY$</a> <br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>