Defining Options for Liberty Service Provider

You can use Access Manager as an identity provider for multiple service providers. You can configure a specific authentication contract for a service provider. If more than one authentication contract is configured for a service provider, the contract having minimum level will be selected.

Step up authentication: When providing authentication to a service provider, Identity Server ensures that the user is authenticated by the required contract. When the user is not authenticated or the user is authenticated, but the authenticated contracts do not satisfy the required contracts, user is prompted to authenticate with the required contract. If no required contract is configured, the default contract is executed.

NOTE:Step up authentication is supported only for Intersite Transfer Service (identity provider initiated) requests on Liberty. It works for both identity provider and service provider initiated requests for SAML 2.0.