Version Affected: All
Overview
This article explains how to add an Extended SAML Attribute to a realm's SAML assertion. The SecureAuth Identity Provider (IdP) includes 10 SAML attributes in the assertion by default; Extended SAML Attributes let a realm send additional attributes beyond those 10. The following steps assume the realm uses Active Directory as its data store.
Add an Extended SAML Attribute
- In the Data tab of the Web Admin UI, go to the Profile Fields section and click Add Property.
- In the new window, type the name of the property to map as the extended SAML attribute — for example, Extended Attribute 1.
- Click Add to display the newly created property.
- Type the name of the Active Directory attribute this property should map to — for example, extensionAttribute1.
- Click Save.
- Go to the Post Authentication tab configured for the realm's SAML Assertion, then click Add Extended SAML Attribute in the Extended SAML Attributes section.
- A message confirms that a new extended attribute has been created.
- With the new extended attribute selected in the Select Extended Attribute drop-down menu, type the name this attribute should use in the SAML assertion, then select the property created in Step 3 from the Attribute Value drop-down menu — for example, label it ExtAttr1 and select Extended Attribute 1.
- Click Save to finish creating the extended SAML attribute.
- To confirm the attribute is included, inspect the realm's SAML assertion with a tool such as a SAML tracer browser extension. The new extended attribute appears as part of the assertion.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.