Software Secure Access
Activity Manage

Encrypted SAML Assertions

Encrypted SAML assertions are a compliance standard in many industries and mitigate the risk of intercepted SAML assertions.

  • Secure Access requires encryption of the whole SAML assertion. Secure Access does not support configuring the IdP to specify EncryptedAttribute or EncryptedID.
  • Secure Access requires SAML assertions encrypted using the key downloaded from Connect > Users and Groups > Configuration Management.
  • Secure Access requires SAML assertions encrypted in sign-then-encrypt order, and will not support SAML assertions encrypted in encrypt-then-sign order.