Add web session scope rules, which examine the contents of the PingFederate validation response and determine whether to grant access to a backend target site based on a match found between the scopes of the validation response and the scope specified in the rule.
Support for the web session support rule might require the PingFederate access token to contain the scope
superuser. To configure this,
see Configuring access token attributes for superuser scope in PingFederate.
- Click Access and then go to .
- Click + Add Rule.
In the Name field, enter a unique name up to 64
Special characters and spaces are allowed.
- From the Type list, select Web Session Scope.
From the Scope list, select the scope you want to match
to values returned from the access token.
This is one scope requirement in the set of scopes associated with the access token.
- From the Rejection Handler list, select the rejection handler you want to associate with this rule.
- Click Save.