Solved

ADFS Claim Rule (Not a member of group sid)

Posted on 2013-01-02
2
1,529 Views
Last Modified: 2016-02-17
I am configuring ADFS Claim Rules to work with SalesForce.  When a specified group id is specified for the claim (check for equals), single sign on works without any problems.  How do you create a claim rule based on AD groups the user is not a member of?
0
Comment
Question by:BlueYonder
2 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 38738878
What are you looking to do? Are you trying to do a negative? I.e. is user Is not a member f X, do y?
You can assign an ad group a mask that is unique using power of 2 for each group the sum of the masks of all the groups a user is a member of, then checking the mask against your rule (logical and) whatever the result will be the matching groups. And you can apply whatever you want.
The above will be what is common.

To do the opposit you can invert the user mask and then logically and with all ones.
This will give the mask of groups that the user is not a member of to do with as you will.

IMHO, it is always best to setup rules based on an affirmative membership rather than trying to prove a negative.  The issue with either approach is that you have to actually enumerate all groups to make sure a group to which a user belongs is not itself a member of yet another group.
0
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 38739008
You can check this out
http://technet.microsoft.com/en-us/library/ff678036(v=ws.10).aspx

ALso thought this article is good ref as well, which shared some part on "- ADFS Claim Rules (Transform)" which states example of "@RuleTemplate = "EmitGroupClaims""

http://blog.force365.com/2012/12/28/salesforce-sso-with-adfs-2-0/

Special customisation
http://social.msdn.microsoft.com/Forums/eu/Geneva/thread/8520c800-189d-4279-8b81-d6a3eb3c6e87
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question