Add Access Filters

AAccess Filters further streamline the users that can access the protected resource with this resource rule.

Connect Access Filters to the Start node and then connect them to the Access Evaluation node as shown in the following figure.

Authentication Context Reference (ACR)

This setting is available for resource rules that protect SAML, OIDC and OAuth, Authentication API, and Identity as a Service applications. It allows a user to authenticate using this resource rule if the authentication request from the client request contains specified Authentication Context Reference (ACR) values, any ACR value, or does not include an ACR value This feature allows the client to influence how the user is authenticated based on ACR requests. For more information, see Add Authentication Context References.

Configure Authentication Context Reference

Domain-based IDP

This setting is available for resource rules configured for the User, User Edit, and Administrator portals, and SAML and OIDC and OAuth applications., It allows a user to authenticate using this resource rule if they belong to a specified Domain-based IDP. For more information, see Manage Identity Providers and webhooks.

Configure a Domain-based IdP

Group

Use this setting to restrict access to users belonging to specific groups. If you want all users to be evaluated by the resource rule, do not add this feature to the graph.

Add a group access filter