Previous Topic: Logging Out of User SessionsNext Topic: Determine how a User Authenticated at an Identity Provider


Authentication Context Processing (SAML 2.0)

The authentication context indicates how a user authenticated at an Identity Provider. The Identity Provider includes the authentication context in an assertion at the request of a Service Provider or based on configuration at the Identity Provider. A Service Provider can require information about the authentication process to establish a level of confidence in the assertion before granting access to resources.

Requesting the Authentication Context

A CA SiteMinder® Service Provider requests the authentication context by including the <RequestedAuthnContext> element in the authentication request to the Identity Provider. Inclusion of this element is based on a configuration setting in the SP->Identity Provider partnership.

Obtaining the Authentication Context

A CA SiteMinder® Identity Provider obtains the authentication context for a user in one of two ways:

This section contains the following topics:

Determine how a User Authenticated at an Identity Provider

Determine Authentication Context and Strength Levels with your Partner

Configure an Authentication Context Template

Configure Authentication Context Processing at the IdP

Configure Authentication Context Requests at the SP