Set the issuance transform rules for AD FS 4.0
- On the Active Directory Federation Services server, download the Workspaces SAML metadata from https://<workspaces.server.address>/saml-idp/saml/metadata.
- Click Start > AD FS Manager.
- In the left-hand menu, click Relying Party Trust.
- In the Relying Party Trust Wizard, click Add Relying Party Trust.
- Select the Claims Aware option.
- In the Select Data Source section, select the Import data about the relying party from a file option.
- Click Browse and navigate to the metadata.xml from step 1.
- Click Next.
- Type a Display name, such as BlackBerry Workspaces, and click Next.
- In the Choose Access Control Policy section, select I do not want to configure access policies at this time. No user will be permitted access for this application or adjust to match your organization's policy and click Next.
- Leave the options in the Ready to Add Trust section at the default values and click Next.
- In the Finish section, select the Configure claims issuance policy for this application option and click Close.
- In the Edit Claim Issuance Policy dialog box, click Add Rule.
- In the Claim rule template list, select Send LDAP Attribute as Claims.
- In the Claim Rule Name field, type Get LDAP Attributes.
-
In the Mapping of LDAP attributes to outgoing claim types table, configure the following LDAP attributes.
- User-Principal-Name = Name ID
- Display-Name = Given Name
- Click OK.