Emitting the Identity2 claim for the relying party
In the AD FS snap-in:
- Select the AD FS > Trust Relationships > Relying Party Trusts node.
-
Select the Relying Party you added previously (e.g.,
"FsOptivaWeb"
). - Click Edit Claim Rules in the Actions pane.
- Click Add Rule.
- Select Add Transform Claim Rule Wizard > Choose Rule Type . Then select Pass Through or Filter an Incoming Claim.
-
Select
Add Transform Claim Rule
Wizard > Configure Claim Rule
and specify this information:
- Claim rule name
-
Specify Pass through Identity2.
- Incoming claim type
-
Specify Identity2.
- Pass through all claim values
-
Select this option.
-
Click
Finish. Then, click
OK to close the
Edit Claim Rules dialog.
Update the WINDOWS_ID fields in the
FSUSER
table with the User Principal Names of the associated Active Directory users. Now, you can use AD FS authentication with OptivaWeb.When accessing the FsOptivaWeb application, use the fully qualified URL, e.g., https://acme.com/FsOptivaWeb. Do not use something like https://localhost/FsOptivaWeb.