Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Step 1 - Pass through Name claims

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-pass-through-or-filter-an-incoming-claim

  • Rule template = Pass Through or Filter an Incoming Claim
  • Incoming claim type = Name
  • Pass through all claim values

...

Step 2 - Pass through Role claims

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-pass-through-or-filter-an-incoming-claim

  • Rule template = Pass Through or Filter an Incoming Claim
  • Incoming claim type = Role
  • Pass through all claim values.

Step 3 - Send GIS Group as iShareUsers Role

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-send-group-membership-as-a-claim

  • Rule template = Send Group Membership as a Claim
  • User’s group = AD\GIS
  • Outgoing claim type = Role
  • Outgoing claim value = iShareUsers

Step 4 - Send Managers Group as iShareAdmin Role

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-send-group-membership-as-a-claim

  • Rule template = Send Group Membership as a Claim
  • User’s group = AD\Managers
  • Outgoing claim type = Role
  • Outgoing claim value = iShareAdmin

...