Commit 8a360f2c authored by Mario Hernandez's avatar Mario Hernandez 💬

Update Integrating_SimpleSAMLphp_with_ADFS_2012R2.md

parent cf0ad18a
......@@ -227,10 +227,11 @@ Now that the Service Provider configuration is complete, SimpleSAMLphp creates t
![](Integrating%20SimpleSAMLphp%20with%20ADFS%202012R2%20-%20lewisroberts.com_html_affe8a2d39ad27ee.png)</font>
3. <font face="Arial, sans-serif">You will be immediately sent off to the ADFS server (or Web Application Proxy depending on how your ADFS farm is configured). Enter your user ID in the format “domain\user” or “user@domain”.
</font>**<font face="Arial, sans-serif">NB</font>**<font face="Arial, sans-serif">: Now, I’ve cheated slightly, I have [enabled Alternate Login ID](https://technet.microsoft.com/en-us/library/dn659436.aspx) so I can sign in with my email address. If you see the article I’ve linked to, Microsoft</font> **<font face="Arial, sans-serif">strongly</font>** <font face="Arial, sans-serif">recommend using the mail attribute for sign in. As they say;</font>_<font face="Arial, sans-serif"><font style="font-size: 10pt" size="2">One of the benefits of this feature is that it enables you to adopt SaaS providers, such as Office 365 with AAD without modifying your on-premise UPNs. It also enables you to support line-of-business service applications with consumer-provisioned identities.</font></font>_<font face="Arial, sans-serif">![](Integrating%20SimpleSAMLphp%20with%20ADFS%202012R2%20-%20lewisroberts.com_html_379b9e352c6417fc.png)</font>
</font>**<font face="Arial, sans-serif">NB</font>**<font face="Arial, sans-serif">: Now, I’ve cheated slightly, I have [enabled Alternate Login ID](https://technet.microsoft.com/en-us/library/dn659436.aspx) so I can sign in with my email address. If you see the article I’ve linked to, Microsoft</font> **<font face="Arial, sans-serif">strongly</font>** <font face="Arial, sans-serif">recommend using the mail attribute for sign in. As they say;</font>_<font face="Arial, sans-serif"><font style="font-size: 10pt" size="2">One of the benefits of this feature is that it enables you to adopt SaaS providers, such as Office 365 with AAD without modifying your on-premise UPNs. It also enables you to support line-of-business service applications with consumer-provisioned identities.</font></font>_<font face="Arial, sans-serif">
![](Integrating%20SimpleSAMLphp%20with%20ADFS%202012R2%20-%20lewisroberts.com_html_379b9e352c6417fc.png)</font>
4. <font face="Arial, sans-serif">Once signed in, you’ll be bounced back to SimpleSAMLphp and shown your claims. If it all went a bit wobbly, double-check everything and then check the Event Viewer for hints as to what could have gone wrong.
![](Integrating%20SimpleSAMLphp%20with%20ADFS%202012R2%20-%20lewisroberts.com_html_18c29eb37d04a3eb.png)</font>
![](/Integrating_SimpleSAMLphp_with_ADFS_2012R2/Integrating_SimpleSAMLphp_with_ADFS_2012R2_-_lewisroberts.com_html_18c29eb37d04a3eb.png)</font>
5. <font face="Arial, sans-serif">Click</font> **<font face="Arial, sans-serif">Logout</font>** <font face="Arial, sans-serif">to test this works as expected – this is where the</font> <font face="Arial, sans-serif"><font style="font-size: 10pt" size="2">sign.logout</font></font> <font face="Arial, sans-serif">declaration in the Service Provider configuration becomes relevant. ADFS</font> _<font face="Arial, sans-serif">requires</font>_ <font face="Arial, sans-serif">the logout to be signed.
![](Integrating%20SimpleSAMLphp%20with%20ADFS%202012R2%20-%20lewisroberts.com_html_e6acf27a085c5342.png)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment