Solved

ADFS Claim Rule (Not a member of group sid)

Posted on 2013-01-02
2
1,446 Views
Last Modified: 2016-02-17
I am configuring ADFS Claim Rules to work with SalesForce.  When a specified group id is specified for the claim (check for equals), single sign on works without any problems.  How do you create a claim rule based on AD groups the user is not a member of?
0
Comment
Question by:BlueYonder
2 Comments
 
LVL 76

Expert Comment

by:arnold
ID: 38738878
What are you looking to do? Are you trying to do a negative? I.e. is user Is not a member f X, do y?
You can assign an ad group a mask that is unique using power of 2 for each group the sum of the masks of all the groups a user is a member of, then checking the mask against your rule (logical and) whatever the result will be the matching groups. And you can apply whatever you want.
The above will be what is common.

To do the opposit you can invert the user mask and then logically and with all ones.
This will give the mask of groups that the user is not a member of to do with as you will.

IMHO, it is always best to setup rules based on an affirmative membership rather than trying to prove a negative.  The issue with either approach is that you have to actually enumerate all groups to make sure a group to which a user belongs is not itself a member of yet another group.
0
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
ID: 38739008
You can check this out
http://technet.microsoft.com/en-us/library/ff678036(v=ws.10).aspx

ALso thought this article is good ref as well, which shared some part on "- ADFS Claim Rules (Transform)" which states example of "@RuleTemplate = "EmitGroupClaims""

http://blog.force365.com/2012/12/28/salesforce-sso-with-adfs-2-0/

Special customisation
http://social.msdn.microsoft.com/Forums/eu/Geneva/thread/8520c800-189d-4279-8b81-d6a3eb3c6e87
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Join & Write a Comment

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now