Configuring SSO for AD FS

Prerequisites

Ensure that you have the following before you start configuring the AD FS server:

  • AD FS account with admin privileges
  • The Clumio metadata XML file, refer to this knowledge base article for instructions on how to get that information from the Clumio dashboard.

Configuring AD FS as an IdP for Clumio Service

  1. To add the Clumio application to AD FS, go to AD Server, click Start > Server Manager.

Pic1.png

  1. Make sure that you can locate the AD FS services in the Server Manager portal. From there, navigate to Tools > AD FS Management.

2.png_

  1. Click Service > Endpoints.

3.png

  1. Ensure that the Metadata XML endpoint is configured as Yes for Enabled and Proxy Enabled columns:

4.png

  1. Now, configure a relying-party Trust for the Clumio service. Under the AD FS Management, click Relying Party Trusts and select Add Relying Party Trust on the panel to the right.

5.png 

  1. When the Add Relying Party Trust wizard displays, click Start.

6.png

  1. In Select Data Source, choose Import data about the relying party from a file and click Browse. Select the Clumio metadata XML file downloaded from the Clumio dashboard and click Next.

7.png

  1. In Specify Display Name, enter a display name for the Clumio service, such as Clumio, then click Next.

8.png

  1. In Choose Access Control Policy, select your appropriate corporate policy, and click Next.

9.png

  1. In Ready to Add Trust, click Next.

10.png

  1. In Finish, keep the Configure claims issuance policy for this application option as checked. Click Close.

11.png

  1. Clicking Close launches the Edit Claim Issuance Policy for Clumio wizard. Select Add Rule to create a new rule for Clumio.

 12.png

  1. In Select Rule Template, leave the values as default and click _Next.

13.png

  1. In Configure Rule, enter the Claim rule name as Clumio. Under the Attribute store option, select Active Directory. Under the Mapping of LDAP attributes to outgoing claim types, add two LDAP Attributes as E-Mail-Addresses and Outgoing Claim Type as E-Mail Addressand Name ID respectively as shown below. Click Finish.

14.png

  1. Click Apply and then click OK.

15.png

  1. Hit Refresh on the AD FS Relying Party Trusts section and confirm the presence of Clumio service.

16.png