I have the following scenario: APM as IdP (works as portal and SP-initiated), v12.0. Multiple SAML IdP resources are configured and showned to the users depending on their AD group membership.
For SP-initiated sessions, I need to perform an AD query in a different way, depending on the SP resource (Issuer). My issue is that the APM doesn’t set any variable for the issuer ID when it receives the AuthnRequest (example such as
urn:federation:MicrosoftOnline
)
Am I overseeing something here? Is there a workaround?
Hm… I am having hard time understanding why you would need to perform AD Query in a different way? If you can post an example, perhaps I can have any better idea. In general, it’s not really possible to do, as the POST URL is the same, and AuthN request does not get parsed until the session is established - so you really need to perform all the checks upon session establishment with the IDP.
This is what I meant: SP-initiated redirect POST to my VS (SAML IdP). A session is established and APM should see the AuthnRequest with Issuer ID. I do then have a logon page and then an ADquery. I would need to do some post-processing but only for one specific IssuerID and not in all cases.
I was thinking you could probably achieve this with an irule that captures the POST request to /saml/idp/profile/redirectorpost/sso and looks for the issuer. You could then set that as a variable to use in the Access Policy.