The Deny authentication action terminates the ongoing authentication with an access denied error. It supports two different operation modes:
Tip
The Curity Identity Server includes other actions that allow denying authentication using criteria such as date/time (e.g. Date/Time Deny Action) and geolocation (e.g. Geolocation Allow or Deny Country Action and Geolocation Impossible Journey Action).
The following configuration options are available:
always
attribute-condition
attribute-condition/name
attribute-condition/source
subject-attributes
context-attributes
action-attributes
attribute-condition/expected-value
true
error
Note that either always or attribute-condition must be specified.