Configure SAML with ADFS
Last modified: Thursday September 02, 2021.
Configure ADFS as your SAML IdP for Alta Video.
Task � Configure ADFS IdP
- Open the ADFS Management console.
- Click Relying Party Trusts.
- In the right-hand panel, click Add Relying Party Trust.
- In the Add Relying Party Trust Wizard, do the following:
- Select the Claims aware radio button and then click Start.
- Select the Enter data about the relying party manually radio button and then click Next.
- In the Display name field, type Alta Aware and then click Next.
- From the Configure Certificate page, click Next.
- Select the Enable support for the SAML 2.0 WebSSO protocol radio button.
- In the Relying party SAML 2.0 SSO service URL field, paste the ACS URL you obtained from Alta Video and then click Next.
- In the Relying party trust identifier field, paste the Entity ID you obtained from Alta Video and then click Add.
- Click Next.
- Select the relevant access control policy and then click Next.
- From the Ready to Add Trust page, click Next and then click Close.
- Double-click the Alta Video Relying Party Trust.
- In the Alta Aware Properties page:
- Click the Signature tab.
- Click Add.
- Select the certificate file (with a .cer extension) that you created by downloading it from your Alta Video deployment.
- Click OK.
- In the middle panel, right-click Alta Aware and then select Edit Claim Insurance Policy.
- Click Add Rule.
- In the Claim Rule Template menu, select Send LDAP Attributes as Claims and then click Next.
- In the Claim rule name field, type Aware claims.
- In the Attribute store menu, select Active Directory.
- Configure your attributes, which are known as claims in ADFS:
- To configure the role attribute:
- In the LDAP Attribute menu, select your preferred role attribute name. This can be an existing attribute or a new custom attribute you create using these instructions. The attribute value must correspond to at least one role in Alta Video. For example, use Department.
- In the Outgoing Claim Type menu, type AvaAwareUserGroup.
- To configure the login name attribute:
- In the LDAP Attribute menu, select User-Principal-Name or your preferred login name attribute name.
- In the Outgoing Claim Type menu, type AvaAwareUsername.
- To configure the email addressees:
- In the LDAP Attribute menu, select E-Mail-Addresses or your preferred user email attribute name.
- In the Outgoing Claim Type menu, type AvaAwareEmail.
- Select the empty bottom row.
- In the LDAP Attribute menu, again select E-Mail-Addresses.
- In the Outgoing Claim Type menu, select E-Mail-Address.
- Click Finish.
- Click Add Rule.
- From the Claim rule template dropdown, select Transform an Incoming Claim.
- In Claim rule name, type Transform Name ID.
- In Incoming claim type, select E-Mail Address.
- In Outgoing claim type, type Name ID.
- In Outgoing name ID format, select Unspecified.
- Click Finish.
- Click OK.
- To obtain the IdP metadata, go to your ADFS. For example, https://adfs.example.com/FederationMetadata/2007-06/Federationmetadata.xml.
An XML file will download to your computer which you will use to complete the next task. - Return to the task in Configure Alta Video to enable SAML single sign-on.
