1. Optional: On the Attribute Sources & User Lookup screen, click Add Attribute Source to configure datastore queries.
  2. On the Contract Fulfillment screen, fulfill the selected contract.
    If the selected closed-ended path contains more than one authentication source, you have access to attributes obtained successfully from the previous authentication sources along the same path.

    For example, referring to the earlier policy in Applying policy contracts or identity profiles to authentication policies, if you select an authentication policy contract for the PingID (Adapter) > Success result, you can map attributes from the HTML Form Adapter and the PingID® Adapter.

    Besides the preceding IdP connection or IdP adapter instance, you can also use dynamic text, attribute mapping expression (if enabled), and tracked HTTP request parameter (if configured) as the source of fulfillment.

  3. Optional: On the Issuance Criteria screen, configure conditions to be validated before issuing an authentication policy contract (see Defining issuance criteria for contract or local identity mapping).
  4. On the Summary screen, review your configuration, modify as needed, and then click Done.
  5. On the Policy screen, continue with the rest of your policy configuration.