Previous Topic: Protect the Artifact Resolution Service at the Identity ProviderNext Topic: Configure a Unique Realm for Each SAML Authentication Scheme


How To Protect Resources with a SAML 2.0 Authentication Scheme

Protect target federation resources by configuring a SiteMinder policy that uses the SAML 2.0 authentication scheme.

To protect a federation resource with a SAML authentication scheme:

  1. Create a realm that uses the SAML authentication scheme. The realm is the collection of target resources that users request.

    Create a realm in one of the following ways:

  2. After you configure a realm, establish an associated rule and optionally, a response.
  3. Group the realm, rule, and response into a policy that protects the target resource.

Important! Each target URL in the realm is also identified in an unsolicited response URL. An unsolicited response is sent from the Identity Provider to the Service Provider, without an initial request from the Service Provider. The unsolicited response contains the target. At the Identity Provider, an administrator must include this response in a link so the Identity Provider can redirect the user to the Service Provider.