Forum Discussion
spalande
Dec 15, 2021Nacreous
Okay. got it. yes, once user is already authenticated by APM, it won't evaluate APM policy for any other URL inside the application with default apm policy. You would need to use something like per request apm policy or step up authentication to re-evaluate for that one URL. You can also try with iRule to remove APM session ACCESS::session remove and then re-evulate.
to be honest, I haven't done this personally but following doc can provide some guidanace.
https://techdocs.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-implementations-12-1-0/8.html
https://devcentral.f5.com/s/articles/apm-full-step-up-authentication-903