<div dir="ltr"><div>On shibboleth IdP 3.4.6<br><br>I have a user with appGroup=jamf_package as an attribute value pair in our LDAP. I have created a group in the SP application called jamf_package and added that user to it.<br><br>I am having an issue where if I set up the sourcevalue with a group prefix like below it doesnt work with the SP. But if I add <ad:DefaultValue>jamf_package</ad:DefaultValue> to the attribute resolver entry below it works and the user is logged in.<br><br><font face="monospace">    <resolver:AttributeDefinition id="jamfgroup" xsi:type="ad:Mapped" sourceAttributeID="appGroup"><br>         <resolver:Dependency ref="ldap_ucsb_edu"/><br>         <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="<a href="http://schemas.xmlsoap.org/claims/Group">http://schemas.xmlsoap.org/claims/Group</a>" friendlyName="group" encodeType="false" /><br>            <ad:ValueMap><br>                <ad:ReturnValue>$1</ad:ReturnValue><br>                <ad:SourceValue>jamf_(\w*)</ad:SourceValue><br>            </ad:ValueMap><br>    </resolver:AttributeDefinition></font><br><br>I am not sure what is wrong because I use this same sourcevalue "prefix" config for other SP's and it works ok.<br></div><div><br></div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Scott Gilbert</div><div>IAM System Admin</div><div>Cloud Collaboration Admin</div><div>Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div></div>