Support for the web session support rule might require the PingFederate access token to contain the scope superuser. To configure this, see Configuring access token attributes for superuser scope in PingFederate.

  1. Click Access and then go to Rules > Rules.
  2. Click + Add Rule.
  3. In the Name field, enter a unique name up to 64 characters long.

    Special characters and spaces are allowed.

  4. From the Type list, select Web Session Scope.
  5. From the Scope list, select the scope you want to match to values returned from the access token.

    This is one scope requirement in the set of scopes associated with the access token.

  6. From the Rejection Handler list, select the rejection handler you want to associate with this rule.
  7. Click Save.