Federation - No Assumption of Active Subscriber Session with IdP After Federated Login, v1.0

After federation login, a RP may not assume that the subscriber has an active session with their IdP.

Assessment Step

1
Assumption of IdP Session (AssumptionofIdPSession)
Is the RP designed to make no assumptions about the status of a subscriber's session at the IdP? Primarily making sure that the software doesn't trigger reauthentication issues in a way that leads to user experience issues or software failures.
Artifact
A1
Provide evidence (e.g. policies, operational details) that the RP does not rely on an existing IdP session for functionality.

Conformance Criteria (1)

C1
The RP SHALL NOT assume that the subscriber has an active session at the IdP past the establishment of the federated log in.
Citation
NIST SP 800-63C
Section 5.3, Paragraph 2