Forum Discussion
FI_2016_187929 Nimbostratus
Nimbostratus
Feb 19, 2015SAML SSO send specific AD Group in Assertion
 We are using F5 APM as IdP and are trying to send AD Groups in our SAML assertion to the SP using the attribute session.ldap.last.attr.memberof.  Some of our AD groups have special character, causing...
Michael_Jenkins Cirrostratus
Cirrostratus
Feb 19, 2015One option would be to look into the ACCESS_POLICY_AGENT event, which can be called during the login flow in the VPE. You could have the iRule parse the memberof session variable (using ACCESS::session data get and populate a new session variable ACCESS::session data set with the desired value(s), then pass that.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects