Solved

ADFS Claim Rule (Not a member of group sid)

Posted on 2013-01-02
2
1,589 Views
Last Modified: 2016-02-17
I am configuring ADFS Claim Rules to work with SalesForce.  When a specified group id is specified for the claim (check for equals), single sign on works without any problems.  How do you create a claim rule based on AD groups the user is not a member of?
0
Comment
Question by:BlueYonder
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 78

Expert Comment

by:arnold
ID: 38738878
What are you looking to do? Are you trying to do a negative? I.e. is user Is not a member f X, do y?
You can assign an ad group a mask that is unique using power of 2 for each group the sum of the masks of all the groups a user is a member of, then checking the mask against your rule (logical and) whatever the result will be the matching groups. And you can apply whatever you want.
The above will be what is common.

To do the opposit you can invert the user mask and then logically and with all ones.
This will give the mask of groups that the user is not a member of to do with as you will.

IMHO, it is always best to setup rules based on an affirmative membership rather than trying to prove a negative.  The issue with either approach is that you have to actually enumerate all groups to make sure a group to which a user belongs is not itself a member of yet another group.
0
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 38739008
You can check this out
http://technet.microsoft.com/en-us/library/ff678036(v=ws.10).aspx

ALso thought this article is good ref as well, which shared some part on "- ADFS Claim Rules (Transform)" which states example of "@RuleTemplate = "EmitGroupClaims""

http://blog.force365.com/2012/12/28/salesforce-sso-with-adfs-2-0/

Special customisation
http://social.msdn.microsoft.com/Forums/eu/Geneva/thread/8520c800-189d-4279-8b81-d6a3eb3c6e87
0

Featured Post

[Webinar] Code, Load, and Grow

Managing multiple websites, servers, applications, and security on a daily basis? Join us for a webinar on May 25th to learn how to simplify administration and management of virtual hosts for IT admins, create a secure environment, and deploy code more effectively and frequently.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conneā€¦
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question