Configuring SSO for Microsoft Active Directory Federation Service (AD FS)

You can integrate the Clumio service with Microsoft Active Directory Federation Service (AD FS).

Prerequisites

Ensure that you have the following before you start configuring the AD FS server.

  • AD FS account with admin privileges

  • The Clumio metadata XML file

For information about retrieving this information from the Clumio dashboard, see Getting SSO service provider information from Clumio dashboard.

Configure AD FS as an IdP for Clumio Service

  1. To add the Clumio application to AD FS, go to AD Server, click Start > Server Manager.

    adfs

  2. Make sure that you can locate the AD FS services in the Server Manager portal. From there, navigate to Tools > AD FS Management.

    adfs

  3. Click Service > Endpoints.

    adfs

  4. Verify that the Metadata XML endpoint is configured as Yes for Enabled and Proxy Enabled columns.

    adfs

  5. Now, configure a relying-party Trust for the Clumio service. Under the AD FS Management, click Relying Party Trusts and select Add Relying Party Trust on the panel to the right.

    adfs

  6. When the Add Relying Party Trust wizard appears, click Start.

    adfs

  7. In Select Data Source, choose Import data about the relying party from a file and click Browse. Select the Clumio metadata XML file downloaded from the Clumio dashboard and click Next.

    adfs

  8. In Specify Display Name, type a display name for the Clumio service, such as Clumio, then click Next.

    adfs

  9. In Choose Access Control Policy, select the corporate policy. appropriate to your requirements, and click Next.

    adfs

  10. In Ready to Add Trust, click Next.

    adfs

  11. In Finish, keep the Configure claims issuance policy for this application option as checked. Click Close.

    adfs

  12. Clicking Close launches the Edit Claim Issuance Policy for Clumio wizard. Select Add Rule to create a new rule for Clumio.

    adfs

  13. In Select Rule Template, leave the values as default and click Next.

    adfs

  14. In Configure Rule, enter the Claim rule name as Clumio. Under the Attribute store option, select Active Directory. Under the Mapping of LDAP attributes to outgoing claim types, add two LDAP Attribute as E-Mail-Addresses and Outgoing Claim Type as E-Mail Addressand Name ID respectively as shown below. Click Finish.

    adfs

  15. Click Apply and then click OK.

    adfs

  16. Hit Refresh on the AD FS Relying Party Trusts section and confirm the presence of Clumio service.

    adfs

×

Loading...