Table of Contents
How To: Configure ADFS on Windows Server 2016
Table of Contents
The installation and configuration of the ADFS service are the sole responsibility of the customer and are not handled by Fotoware. Before configuring the Identity Provider in Fotoware Alto (formerly Picturepark Content Platform), ADFS must be fully installed and correctly configured.
For more information, see the official Microsoft documentation.
Here you find an overview of a generic ADFS setup on Windows Server 2016.that
- Client ID displayed at 0:20.
There is a Microsoft limitation in ADFS 2.0 that prevents the use of Domain Local Groups in a claim. Choose global or universal groups. There is more information about this limitation at microsoft.com
For nested groups, child groups cannot access Fotoware Alto if the parent group does not have access.
Basic configuration of ADFS
- On Windows Server 2016, open ADFS Management.
- Right-click on Application Groups and select Add Application Group.
- In the Application Group Wizard, enter a name, and under Client-Server applications, select the web browser accessing a web application template.
- Select Next.
- Copy the Client Identifier value. It will be used later in the identity server configuration.
- Enter the Identity Server URL as your Redirect URI (see Help > System Information). This is the URL where your authenticated users are redirected, which is the identity server URL.
- Select Next on the Apply Access Control Policy page.
- On the Summary screen, select Next.
- On the Complete screen, select Close.
Claims configuration ADFS
- Now, on the right-click the new Application Group and select Properties.
- Double-click on web application.
- To configure claims, go to the Issuance Transform Rules tab.
- Select Add Rule and select Send LDAP Attributes as Claims as a rule template, then select Next.
- To propagate the email address, configure a rule as in the example below:
- To propagate AD groups, configure a rule as in the example below:
- To propagate user name information, configure a rule as in the example below: