Creating relying party claim issuance authorization rules

You can optionally create an issuance authorization rule to control which users can access IBM® Verify.

Procedure

  1. Go to the ADFS Management Console.
  2. Click Trust Relationships > Relying Party Trusts in the ADFS folder.
  3. Select the relying party trust that you previously created.
    The trust is displayed in the Actions pane.
  4. Click Edit Claim Rules.
    Actions pane
  5. Select the Issuance Authorization Rules tab.
  6. Remove the default Permit Access to All Users rule.
  7. Add a rule called Cloud_Identity_Users Only.
    Use the template Permit or Deny Users Based on an Incoming Claim. Configure it as shown in the following figure.
    1. Select Group SID from the menu for the Incoming claim type.
    2. Use Browse to select the group name in your Active Directory whose members are going to access SaaS apps through IBM Verify.
      Note: In many organizations, this group includes all employees and this selection is not needed.
    Issuance Authorization Rules pane