Federation - No Assumption of Assertion Equivalence Based on Supplementary Attributes, v1.0

Relying Parties should not assume the ability to fetch supplemental attributes is equivalent to processing assertions.

Assessment Step

1
Supplemental Attribute Query (SupplementalAttributeQuery)
If the RP fetches additional identity attributes from the IdP, does the RP not treat this ability as equivalent of processing the assertion?
Artifact
A1
Provide evidence (e.g. policies, operational details) that if the RP uses supplemental attribute queries it does not substitute this ability for assertion processing.

Conformance Criteria (1)

C1
The RP MAY fetch additional identity attributes from the IdP in one or more separate transactions using an authorization credential issued alongside the original assertion. The ability to successfully fetch such additional attributes SHALL NOT be treated as equivalent to processing the assertion.
Citation
NIST SP 800-63C
Section 6, Paragraph 7