Federation Security Services Guide › Use an Attribute Authority to Authorize Users › Set up a SAML Requestor to Generate Attribute Queries › Enable Attribute Queries and Specify Attributes
Enable Attribute Queries and Specify Attributes
To enable the SAML Requester to send an attribute query
- Log on to the FSS Administrative UI.
- Access the Authentication Scheme Properties dialog for the SAML 2.0 authentication scheme that protects the resource that will be protected based on a user attribute.
- Click on Additional Configuration.
The SAML 2.0 Auth Scheme Properties dialog opens.
- Click on the Attributes tab.
- Click Add.
The Add Attribute dialog opens.
- Enter values for the following fields:
- Local Name
- Attribute Name
- Name Format
Note: You can click Help for a description of fields, controls, and their respective requirements.
- Click OK to save your changes.
You return to the Attributes dialog.
- In the Attribute Query group box, select Enabled and enter a value for the Attribute Service field.
- Optionally, select the following check boxes:
- Sign Attribute Query
- Require Signed Assertions
- Get All Attributes
- Click OK.
The Name IDs tab opens and a message is displayed instructing you to specify an attribute name for the name identifier.
- Configure a NameID. This NameID configured in the SAML 2.0 Auth.Scheme Properties is included in the attribute query for use by the Attribute Authority.