Federation - Minimization of Attributes Transmitted, v1.0

Identity Providers must only transmit attributes that are explicitly requested by RPs.

Assessment Step

1
Minimize Attributes Transmitted (MinimizeAttributesTransmitted)
Does the IdP only end the requested attributes to the RP? This attributes may be requested at the time of the authentication event or in advance as part of the trust configuration.
Artifact
A1
Provide evidence (e.g. policies, operational samples) that all assertions include only those attributes requested by RPs.

Conformance Criteria (1)

C1
The IdP SHALL transmit only those attributes that were explicitly requested by the RP.
Citation
NIST SP 800-63C
Section 7