Creating relying party trust issuance transform rules

Add issuance transform rules that create the SAML assertion that ADFS sends to Verify.

About this task

You must create a rule that is called Send LDAP attributes by using the template Send LDAP Attributes as Claims. This rule maps the E-Mail-Addresses attribute to E-Mail-Address. Add other attributes from Active Directory that your organization needs for connecting to SaaS providers. Map them to standard or custom SAML attribute names as needed by your organization.

Procedure

  1. Select your relying party and click Edit Claim Rules.
  2. Click Add Rule on the Edit Claim Rules window.
    The graphic shows the contents of the Issuance Transform Rules tab.
  3. Create the Send LDAP Attributes rule.
    1. Click Add Rule on the Issuance Transform Rules tab.
    2. Select Send LDAP Attributes as Claims from the template menu and click Next.
    3. Type or select the following settings.
      The graphic lists the LDAP attributes that are mapped to the out going claim type.
      Note: Add any other LDAP attributes that you want to be sent over as claims.
    4. Click Finish.
  4. Create the Email to NameID rule.
    1. Click Add Rule on the Issuance Transform Rules tab.
    2. Select Transform an Incoming Claim from the template menu and click Next.
    3. Type or select the following settings.
      The graphic shows the content of the email to NameID rule template.
    4. Click Finish.
  5. Add application roles.
    If you want to add application roles for a group to represent admin and standard Verify user, use the following values. For admin users, use the admin value for the Outgoing claim value and for standard user, use the user value for the Outgoing claim value.
    For example: Admin group.
    1. Select Send Group Membership as a Claim from the template menu and click Next.

    2. Specify the unique name for your rule in Claim rule name field.
      For example: Send admin group.
    3. Click Browse to select your user group that represents the admin users on Verify from User’s group.
    4. Select Group from the Outgoing claim type menu.
    5. Provide a name for the Outgoing claim value.
      For example: admin.
    6. Click Finish.