<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p>We have a vendor that doesn't do authorization on their side
(yes, I know...) A workaround they have suggested is:<br>
<br>
<blockquote type="cite"><span style="font-size: 11pt">They could
also independently explore that if the user is “not a member
of the portal group” that they amend the SAML response to
instead send a “Responder” (e.g. not “success”) status from
the IdP which should trigger them to receive the generic Login
Failed error message as context.</span></blockquote>
</p>
<p>I'm wondering if there is a reasonable way to accomplish this in
the IdP (5.1.3) without too much work. We have the group
membership available as an attribute at attribute resolution
time. Ideally it would be configurable for just this SP (e.g. as
their own RelyingParty configuration).</p>
<p>Any suggestions on an approach?<br>
</p>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</body>
</html>