ADFS 2.0 - Conditionally issuing claims


(is best place this? geneva forum has been archived.)

hi has got ideas how solve problem: access given area of relying party's application need specify area in claim.

i'm using ad group conditionally issue claim - there 2 possible claim values need issue , given user required access 1 area or other, not both.  have rule checks if user part of ad group, if are, issues claim value1 otherwise issues claim value2.

we have need add third area both sets of users need access.  claim needs issued dynamically.  i'd able issue claim based on idp initiated login url parameter.

e.g.

access portal1 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com&portal=portal1

access portal2 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com&portal=portal

 

one option might have been have multiple relying parties configured end @ same rp have different rule sets e.g.

access portal1 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com.portal1

access portal2 @ myrp.com:
https://federate.mydomain.com/adfs/ls/idpinitiatedsignon.aspx?logintorp=https://myrp.com.portal2

 

problem is, adfs won't allow multiple rps created when have same signing certificate.

 

i'm interested know claims in incoming set. know they're ad attributes there others e.g. "authentication time stamp" doesn't come ad must generated adfs. else in there check against. somthing referingurl - check user redirected , determine claim issue.

 

any ideas appreaciated.

 

cheers,

rhys

 

http://blog.rhysgoodwin.com/

 

hi,

 

please try visit adapt forum better resolution.

 

http://social.msdn.microsoft.com/forums/en-us/geneva/threads/

 

thanks understanding!

 

best regards

elytis cheng

 


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607