27.10.3 Creating the Relying Party Trust on ADFS

  1. On the ADFS Management console, click Relying Party Trusts > Add Relying Party Trust.

  2. Select Claims aware and click Start.

  3. To import StoreFront metadata, perform the following:

    1. Select Import data about the relying party from a file.

    2. Specify StoreFront metadata URL in https://<storefront_server>/Citrix/<StoreAuth>/SamlForms/ServiceProvider/Metadata format.

    3. Click Next.

  4. Specify Display Name and Notes for StoreFront and click Next.

  5. Select Permit everyone from Choose an access control policy list to configure access control policy for ADFS and click Next.

  6. Verify the values imported from the StoreFront metadata and Click Next.

  7. Select Configure claims issuance policy for this application and click Close.

  8. Select the trust created for StoreFront on the Relying Party Trusts and click Edit Claim Rules.

  9. In the Issuance Transform Rule tab, add three rules:

    • To add the first rule, perform the following steps:

      1. Click Add Rule.

      2. Select Send LDAP Attributes as Claims from Claim Rule Template.

      3. Specify Claim rule name.

      4. Select Active Directory from Attribute Store.

      5. Select User-Principal-Name from LDAP Attribute.

      6. Select Name ID from Outgoing Claim Type.

      7. Click Save.

    • To add the second rule, perform the following steps:

      1. Click Add Rule.

      2. Select Pass Through or Filter an Incoming Claim from Claim Rule Template and click Next.

      3. Specify Claim rule name.

      4. Select Name ID from Incoming Claim Type.

      5. Select Unspecified from Incoming name ID format.

      6. Select Pass through all claim values.

      7. Click OK.

    • To add the third rule, perform the following steps:

      1. Click Add Rule.

      2. Select Send LDAP Attributes as Claims from Claim Rule Template.

      3. Specify Claim rule name.

      4. Select Active Directory from Attribute Store.

      5. Map the LDAP attributes as follows:

        • LDAP attribute 1:

          1. Select Surname from LDAP Attribute.

          2. Select Surname from Outgoing Claim Type.

        • LDAP attribute 2:

          1. Select Given Name from LDAP Attribute.

          2. Select Given Name from Outgoing Claim Type.