How To: Add an Extended SAML Attribute to a SAML Assertion

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to add an Extended SAML Attribute to a realm's SAML assertion. The SecureAuth Identity Provider (IdP) includes 10 SAML attributes in the assertion by default; Extended SAML Attributes let a realm send additional attributes beyond those 10. The following steps assume the realm uses Active Directory as its data store.

     

    Add an Extended SAML Attribute

    1. In the Data tab of the Web Admin UI, go to the Profile Fields section and click Add Property.

    Data tab Profile Fields section with the Add Property button highlighted.

    1. In the new window, type the name of the property to map as the extended SAML attribute — for example, Extended Attribute 1.

    New property window with the property name Extended Attribute 1 entered.

    1. Click Add to display the newly created property.

    Profile Fields list showing the newly created Extended Attribute 1 property.

    1. Type the name of the Active Directory attribute this property should map to — for example, extensionAttribute1.

    Property mapping field with extensionAttribute1 entered as the Active Directory attribute.

    1. Click Save.

    Data tab showing the Save button for the new property mapping.

    1. Go to the Post Authentication tab configured for the realm's SAML Assertion, then click Add Extended SAML Attribute in the Extended SAML Attributes section.

    Post Authentication tab Extended SAML Attributes section with the Add Extended SAML Attribute button highlighted.

    1. A message confirms that a new extended attribute has been created.

    Confirmation message indicating a new extended attribute has been created.

    1. With the new extended attribute selected in the Select Extended Attribute drop-down menu, type the name this attribute should use in the SAML assertion, then select the property created in Step 3 from the Attribute Value drop-down menu — for example, label it ExtAttr1 and select Extended Attribute 1.

    Extended SAML Attribute configuration with the attribute labeled ExtAttr1 and Extended Attribute 1 selected as the value.

    1. Click Save to finish creating the extended SAML attribute.

    Extended SAML Attributes section showing the Save button for the new attribute.

    1. To confirm the attribute is included, inspect the realm's SAML assertion with a tool such as a SAML tracer browser extension. The new extended attribute appears as part of the assertion.

    SAML assertion captured by a SAML tracer tool, showing the new extended attribute included in the assertion.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.