Federation › Federation Security Services Guide › Authenticate SAML 1.x Users at a Consumer › How To Protect a Resource with a SAML 1.x Authentication Scheme › Form the Policy to Protect the Target Resource
Form the Policy to Protect the Target Resource
The general process for creating the policy is as follows:
Note: This assumes that a user directory has already been configured.
- Create a SAML 1.x authentication scheme.
- Associate the SAML authentication scheme with a realm.
- Within the realm, create one rule with a Web Agent action or two rules, one with a Web Agent action and the other as an authenticating event with the OnAuthReject action.
- Optionally, if you configured an OnAuthReject rule, configure a Web-Agent-OnReject-Redirect Response attribute that contains a value of a URL where the rejected user should be redirected. We recommend using a static attribute value.
- Create a policy grouping the realm, rule, and response together.
- Exit the Policy Server User Interface.