the user against a SAML 2.0 IdP, and and grants access to directories depending on attributes received from the IdP.