Configure Identity Provider attribute for Session Access
Use Identity Provider (IDP) attribute created from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) for removing or restricting user session access to the instance.
始める前に
Role required: security_admin
Enable the Enable Session Access property.
注:
To use the Session Access role configuration, you must elevate your role to security_admin.
Session Access can be controlled by the created policy and selected action when performing the configuration. Some of the scenarios are as follows:
- If the Policy is true, and the roles action is set to Remove Roles along with the IDP attribute input and condition, then the selected roles and its associated child roles are removed for the user when trying to log in to the instance.
- If the Policy is true, and the roles action is set to Limit To Roles along with the IDP attribute input and condition, then only the selected roles and its associated child roles are assigned to the user when trying to log in to the instance.
The following procedure shows steps to configure the IDP attribute from the SAML response a policy input to control session access.