Configure Groups in ADFS

Create or configure Active Directory groups that you want to map to Security Groups in CSM. Users are automatically added to the mapped CSM Security Group when their account is created or updated.

To configure groups in ADFS:

  1. Open the AD FS Management tool.
  2. From the navigation pane, expand Trust Relationships, and then select Relying Party Trusts.
  3. Select the CSM server that is configured for SAML.
  4. Select Edit Claims Rules, and then select Add Rule.
  5. From the Add Transform Claim Rule Wizard, select the Send Group Membership as a Claim rule template, and then select Next.
  6. Add the following claim rule properties:
    Claim rule nameProvide a name, such as Admin or IT Service Desk Level 1. For easier maintenance, choose a name that matches Security Group names in CSM.
    User's GroupSelect Browse, and then add the domain name group you want to map to CSM Security Groups. For example, add Domain Admins if you want to automatically add users in this group to the Admins Security Group in CSM.
    Outgoing Claim TypeSelect Group.
    Outgoing Claim ValueProvide a name for the group. This is the name you will use to map the ADFS group to a CSM Security Group.

  7. Record the group names you added so have the names when you map them to Security Groups in CSM.
  8. Select Finish.
  9. Repeat this process for each ADFS group you want to map to a CSM Security Group.
  10. Map the ADFS groups to CSM Security Groups. See Map SAML Security Groups to CSM Security Groups.