Previous Topic: Define Indexed Endpoints for Different Single Sign-on Bindings

Next Topic: Determine Digital Signing Options

Enforce the Authentication Scheme Protection Level for SSO

When a user requests a federated resource, they must have a SOA Security Manager session. If a user does not have a SOA Security Manager session, the user is redirected to the Authentication URL to establish a session. The authentication scheme protecting the Authentication URL is configured with a particular protection level. This protection level must be the same or greater than the authentication level you configure for the SAML Service Provider configuration.

If the protection level for the Authentication URL is less than the Authentication Level set in the Administrative UI, SOA Security Manager does not generate an assertion.