Previous Topic: How to Disable Client LoopbackNext Topic: Add and Grant Permission to CA SiteMinder® Users


Disable Client Loopback

The CA SiteMinder® Agent for SharePoint has a client loopback feature that lets you create policies in your SharePoint environment using directory attribute values that do not yet exist.

For example, suppose that your directory server contains an attribute named employeeType, and the employeeType attribute uses one of the following values for each user:

For example, suppose you want to create an attribute value for the employeeType attribute named Vendor in your directory servers to use with SharePoint.

If a different group in your organization manages the directory servers, that task is beyond your control. The Claims Provider creates placeholders for the new attribute values using the loopback feature.

In this example, use the loopback feature so that the Vendor attribute value exists in your SharePoint environment it appears in the directory servers. New attribute values let you create SharePoint policies whenever you want, without waiting for your administrator to add the actual attribute values to your directory.

If you do not need to add attributes using the SharePoint people picker before they exist in your user directories, disable the client loopback feature. Leaving client loopback enabled when the directory attributes exist returns duplicates in the SharePoint people picker.

Follow these steps:

  1. Log in to your SharePoint central administration server.
  2. Click Start, All Programs, Microsoft SharePoint 2010 Products, SharePoint 2010 Management Shell.

    The management shell command-line window opens.

  3. Navigate to the following directory:
    C:\Program Files\CA\SharePointClaimsProvider\scripts
    
  4. Enter the following command:
    .\Set-SMClaimProviderConfiguration.ps1 -DisableLoopBackSearch
    

    Loopback search is disabled.