Add an AD FS Claims Provider service
If your organization has apps that use
Active
Directory
Federation Services (AD FS) forms-based authentication, you can add an AD FS Claims Provider service so that Enterprise Identity
can authenticate the AD FS apps using the forms authentication type.
Enterprise Identity
supports AD FS 2019 and later- Verify that the AD FS role has been added to theActive Directoryserver.
- Verify thatUEMis connected to theActive Directoryserver that has the AD FS role.
- In theUEMmanagement console, clickSettings>BlackBerry Enterprise Identity>Services.
- In theSAML Servicestable, click .
- ClickADFS Claims Provider.
- If you want to enable ZSO for users, select theAllow Mobile ZSO when specified by authentication policyandAllow Kerberos Desktop ZSO when specified by authentication policycheck boxes.
- Type a name and description for the service.
- In theService provider entity IDfield, enterhttp://<adfs_host>/adfs/services/trust, whereadfs_endpointis the name of theActive Directoryserver that has the ADFS role.
- In theAssertion consumer service POST URLfield, enterhttp://<adfs_host>/adfs/services/ls, whereadfs_endpointis the name of theActive Directoryserver that has the ADFS role.
- In theSingle logout service URLfield, enterhttp://<adfs_host>/adfs/services/ls, whereadfs_endpointis the name of theActive Directoryserver that has the ADFS role.
- ClickSave.
Assign the service to users.