Известные ограничения
Если у пользователя нет полей из Mapping переменных (например, почты) необходимо выполнить следующие действия:
- создать правила для Relying Party Trust для ранее созданного стенда;
- правой кнопкой мыши нажать на созданный ранее стенд Edit Claim Issuance Policy (рис.):
Правило 1:
c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]
=> issue(store = "Active Directory", types = ("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname"), query = ";objectSID,mail,givenName,sn;{0}", param = c.Value);
Правило 2:
c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"]
=> issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");
Если добавить Relying Party Trust не получается из-за отсутствия поддержки TLS выше версии 1.0 на стороне ADFS, то следует рассмотреть рекомендации по внесению изменений от Microsoft, приведенные в соответствующих статьях.
Чтобы добавить фото пользователя из Active Directory, необходимо выполнить команду:
c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]
=> issue(store = "Active Directory", types = ("thumbnailPhoto"), query = ";thumbnailPhoto;{0}", param = c.Value);