<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>We have a vendor that doesn't do authorization on their side
      (yes, I know...) A workaround they have suggested is:<br>
      <br>
      <blockquote type="cite"><span style="font-size: 11pt">They could
          also independently explore that if the user is “not a member
          of the portal group” that they amend the SAML response to
          instead send a “Responder” (e.g. not “success”) status from
          the IdP which should trigger them to receive the generic Login
          Failed error message as context.</span></blockquote>
    </p>
    <p>I'm wondering if there is a reasonable way to accomplish this in
      the IdP (5.1.3) without too much work.  We have the group
      membership available as an attribute at attribute resolution
      time.  Ideally it would be configurable for just this SP (e.g. as
      their own RelyingParty configuration).</p>
    <p>Any suggestions on an approach?<br>
    </p>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>