Forum Discussion
Granular Access control policies
We are trying to use the Big IP system as a SAML service provider and PingFederate as a SAML Identity Provider. Is it possible to create an access policy which allows/denies user to access a particular protected resource based on user atrributes or groups using F5 Big IP APM?
- youssef1Cumulonimbus
Hello,
Yes of course, If you host your SP on F5 you can allows/denies user to access a particular SAML Attributes or LDAP attributes...
You can also using per request policy allow user to access to a specific URI depending an LDAP/AD Attributes...
give me exactly your need and I can help you to go ahead.
regards
- Manoj_ChavaliNimbostratus
Hi,
Thank you for the information. Could you please point me towards any document on how to implement the authorization based on the LDAP attributes?
- youssef1Cumulonimbus
Hello,
You don't have a specific documentation for your need. In fact you have to use a generic access policy for authentication and LDAP query in order to retrieve needed attribute.
Then you can use an per-request-policy in order to restrict URL access by LDAP/AD GRP or other.
I alread implement this need for an custoer and I use Datagroup in order to set right:
grp_A /uri1
grp_B /uri2
grp_C /uri3
try to implent an per-request-policy... if you encouter a problem keep me in touch.
regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com