Set the issuance authorization rules
On the
Issuance Authorization Rules
tab you configure the send LDAP attributes as claims rule and the permit all users rule. The permit all users rule is optional. Consult your AD FS IT team to determine if this rule is required for your organization.- Access the Edit Claim Rules application.
- ClickRelying Party Trust.
- Right-click the newBlackBerryWorkspacesParty Trust and selectEdit Claim Rules.
- Click theIssuance Transform Rulestab.
- ClickAdd rule...>Send LDAP Attributes as Claims>Next.
- Assign values to the rule parameters.Rule parameterValueClaim Rule NameGet LDAP AttributesAttribute StoreActive Directory
- Configure the LDAP attribute, and clickOK.LDAP attributeOutgoing claim typeEmail-AddressesEmail address
- ClickAdd rule...>Permit All Users>Next>Finish.