Have IDP to check user device before saml authentification
Does anybody have a suggestion howto do a check on the users device before allowing a users to authenticate with Saml (it could be any auth class of course)
This use case is Cisco Any connect vpn that supports saml as authentication method but then is not able to do client pre check to verify that the device is a organization managed device.
We would like to check that the client got a couple of certificates in cert store or if there is a given registry key in the device.
Anybody got a suggestion how to do that?