Attribute sharing policies (addon federation)

Description

Soffid allows you to define security rules as policies that apply to any attribute that should be delivered from identity providers to service providers.

Please note that at least one policy must be created to return attributes to service providers. If there is no policy, or none is met, no attributes will be sent.

When logging in with a service provider, all policies are validated and more than one may be applied. In this case, the sum of all attributes contained in those policies will be returned.

Please note that this screen is available in the federation addon.

Screen overview

image.png

image.png

Standard attributes

Table attributes

Policy attributes

Condition attributes

It is a boolean expression to be evaluated. The condition will be evaluatuated when the Allow value was yes. You can use the conditions to configure the conditions policy and to configure the shared attributes.

Type: the boolean operator are the follow:

Actions

Table actions

Add new

Allows you to add a new policy in the system. To add a new it is necessary to fill in the required fields.

Delete policy

Allows you to remove one or more policies by selecting one or more records and next clicking this button. To perform that action, Soffid will ask you for confirmation, you could confirm or cancel the operation.

Policy actions

Delete policy Allows you to save the data of a new Attribute sharing policy or to update the data of a specific Attribute sharing policy. To save the data it will be mandatory to fill in the required fields.
Add new Allows you to add a new shared attribute in the policy. To add a new it is necessary to fill in the required fields.
Delete attribute Allows you to remove one or more shared attribute by selecting one or more records and next clicking this button. To perform that action, Soffid will ask you for confirmation, you could confirm or cancel the operation.
Undo Allows you to quit without applying any changes made.
Apply changes Allows you to save the data of a new Metada object or to update the data of a specific Metadata object. To save the data it will be mandatory to fill in the required fields.

Attributes actions

Close Allows you to close the popup window. Please note that the changes have not been saved, you must click Apply changes button.

Examples

Examples for defining conditions in an attribute sharing policy.

Example 1

Return a list of attributes for any trusted service provider.

image.png

Example 2

Rule that applies to all the service providers belonging to the "SOFFID" entity group.

image.png

Example 3

Rule that only applies to the service provider ‘TestSP’.

image.png



Revision #11
Created 19 July 2025 12:20:50 by Sion Vives
Updated 22 September 2025 13:01:07 by Sion Vives