Assembly: System.IdentityModel (in System.IdentityModel.dll)
Use the SamlSecurityToken security tokens. When the STS issues the security token, it can specify the URI of the Web services for which the security token is intended by adding a SamlAudienceRestrictionCondition to the security token. That allows the SamlSecurityTokenAuthenticator for the recipient Web service to verify that the issued security token is intended for this Web service by specifying that this check should happen by doing the following:property in a federated application that utilizes a security token service (STS) that issues
Specify the set of valid URIs, by adding the URIs to the AllowedAudienceUris collection.
When the BearerKeyOnly, an incoming non-endorsing SamlSecurityToken must contain a SamlAudienceRestrictionCondition and the Audiences collection must contain a URI that matches one of the valid URIs specified in the AllowedAudienceUris collection. A non-endorsing or bearer token is a security token that is included in the message and not used to sign any part of the message.property is set to
Optionally, override the ValidateAudienceRestriction method to specify the validation algorithm to use for the allowed URI.
Available since 3.0