<div dir="ltr"><div dir="ltr"><div class="gmail_default" style="font-family:monospace,monospace;font-size:small;color:#000000">That seems like something the SP should be able to do if they can't consume the attributes as they are natively released... <a href="https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334474/TransformAttributeResolver">https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334474/TransformAttributeResolver</a> comes to mind?</div><div class="gmail_default" style="font-family:monospace,monospace;font-size:small;color:#000000"><br></div><div class="gmail_default" style="font-family:monospace,monospace;font-size:small;color:#000000">Caveat - I am replying more on my understanding of how it should work than on actual implementation experience/knowledge :)</div><div class="gmail_default" style="font-family:monospace,monospace;font-size:small;color:#000000"><br></div></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><b>Bruce Timberlake</b><br><b>Sr Application Systems Administrator</b><span style="font-family:arial,sans-serif;font-size:13px;letter-spacing:0.2px;color:rgb(34,34,34)">, Identity and Access Management Services</span><div style="color:rgb(34,34,34);font-family:arial"><div style="font-family:Arial,Helvetica,sans-serif">ITS - Information Assurance</div><div style="font-family:Arial,Helvetica,sans-serif">University of Michigan</div></div></div></div><input name="virtru-metadata" type="hidden" value="{"email-policy":{"state":"closed","expirationUnit":"days","disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"persistentProtection":false,"expandedWatermarking":false,"expires":false,"isManaged":false},"attachments":{},"compose-id":"5","compose-window":{"secure":false}}"></div>