<html><body><div dir="ltr">A well know service provider (Kaltura, aka MediaSpace) is deploying a revised integration and has asked/told us to “remove" the default IdP setting x-frame-options=DENY. I do not have deep understanding of the issue, but it seems an unnecessary/unwarranted reduction in the IdP’s security posture. Have others encountered similar request and if so, what are you doing in response?<div><br></div><div dir="ltr">David St Pierre Bantz</div><div dir="ltr">U Alaska IAM</div></div></body></html>