Troubleshooting: Extended SAML Attributes Are Passed, But Do Not Have a Value

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    When using SecureAuth's Extended SAML Attributes feature, a SAML trace may show that an attribute's name is being passed to the Service Provider (SP), but the attribute has no value.
     
     

    Cause

    Each Extended SAML Attribute has a Group Filter Expression field that determines which Active Directory (AD) group membership the attribute's value applies to. This field takes a regular expression, and if it is left blank, no group matches — so the SP receives the attribute's name but never receives a value for it.
     
     

    Resolution

    Enter a regular expression in the Group Filter Expression field that matches at least one AD group the authenticating users belong to. Entering .* matches every group and resolves the missing value in most cases; use a more specific expression if the attribute's value should only apply to particular groups.

    Extended SAML Attributes configuration panel showing an example attribute named Test Attribute, with Format set to Basic and Value set to Test Value; the Group Filter Expression field is highlighted and set to .*

    The screenshot above shows the Group Filter Expression field set to .* on an example Extended SAML Attribute.
     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.