You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/docs/cloudflare-one/identity/idp-integration/adfs.mdx
+8-3Lines changed: 8 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,10 +17,10 @@ Active Directory is a directory service developed by Microsoft for Windows domai
17
17
18
18
To get started, you need:
19
19
20
-
- An Active Directory Domain Controller where all users have an email attribute
21
-
- Generic SAML enabled for your Access Identity Provider (IdP)
20
+
- An Active Directory Domain Controller where all users have an email attribute.
21
+
- Generic SAML enabled for your Access Identity Provider (IdP).
22
22
- A Microsoft server running with Active Directory Federation Services (AD FS) installed. All screenshots in these instructions are for Server 2012R2. Similar steps will work for newer versions.
23
-
- A browser safe certificate for Active Directory Federation Services (AD FS)
23
+
- A browser safe certificate for Active Directory Federation Services (AD FS).
24
24
25
25
Once you fulfill the requirements above, you are ready to begin. Installation and basic configuration of Active Directory Federation Services (AD FS) is outside the scope of this guide. A detailed guide can be found in a [Microsoft KB](<https://docs.microsoft.com/en-us/previous-versions/dynamicscrm-2016/deployment-administrators-guide/gg188612(v=crm.8)>).
26
26
@@ -126,6 +126,11 @@ To create Claim Rules:
126
126
127
127
Both Claim Rules are now available to export to your Cloudflare Access account.
128
128
129
+
:::note
130
+
131
+
If you wish to use AD FS groups in your SAML claims, use `token-groups - unqualified names` instead of `is-member-of-DL`.
132
+
:::
133
+
129
134
## Export the certificate
130
135
131
136
Now you'll configure Cloudflare to recognize AD FS by extracting the _token-signing certificate_ from AD FS.
0 commit comments