Forum Discussion
SAML Idp-Initiated Connections
Hi,
Actually, when you bind your external SP connector to your local IDP, this is not a SP initiated (not really). It depends how you configure your APM IDP policy. You can use an APM as IDP for SP initiated and IDP initiated. It depends the way your set your policy. If you use SAML resources assigned to your webtop, you can use APM as SP and IDP initiated. If you do not assign any SAML resource or webtop, you can not use IDP initiated.
I mean, if you reach SFDC in first (SP initiated), you will be redirected to the IDP for auth and redirected to SFDC when done. If you reach the IDP in first (IDP initiated), you will be prompted with your SAML resource (SFDC) on the webtop.
If the second vendor only supports IDP initiated, you need to use a SAML resource in order to push the SAML assertion at the first SP connection. SAML resource needs a webtop. I don't know if we can force APM to start a SAML resource after login so that user does not see the webtop.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com