Configure ADFS for your user authentication in Brandfolder.
USM Content
Set up ADFS
To set up ADFS with Brandfolder, you need:
- An Active Directory instance where users have an email address attribute.
- A metadata file from Brandfolder Support used for the import.
- An SSL certificate to sign your ADFS login page, and the fingerprint of that certificate.
Add a relying trust party
- Log in to the ADFS Server.
- Right-click Relying Party Trust on the left side of the table.
- Select Add Relying Party Trust...
Configure the relying party trust wizard
- Select Start.
- On the Select Data Source Screen, choose Import data about this relying party from a file.
- Pick Browse and choose the Brandfolder metadata file.
- Importing this data allows you to select Next to Configure Multi-factor Authentication Now - leave the defaults, and choose Next.
- On Choose Issuance Authorization Rules, select Permit all users.
- The following screen shows an overview of your settings. Then, select Next.
- On the closing screen, pick Close, and open the Claim Rules Editor.
Creating claim rules
- The Claims Rule editor opens automatically. To create a new Rule, select Add Rule.
- Select Send LDAP Attributes as Claims and select Next.
- On the screen, set the LDAP Attribute to E-Mail-Addresses and set Outgoing Claim Type to E-Mail Address.
- Choose OK to save the rule.
- Create another new rule by selecting Add Rule. Then, select Transform an Incoming Claim from the dropdown.
- On the following screen, choose the following:
- E-mail Address as Incoming Claim Type.
- Outgoing Claim Type as Name ID.
- Outgoing Name ID Format as Email.
- Leave the default of Pass through all claim values.
7. Select OK to create the claim rule.
Set up a full-name claim
- Brandfolder recommends sending the first and last name along with the email address of the user.
- Create another new rule by selecting Add Rule.
- Set one LDAP Attribute to Surname and one to Given-Name.
- Set the Outgoing Claim Type to Surname and one to Given-Name.
- Select OK to create this rule, then OK again to complete the rules.
Test the configuration
- Now the configuration can be tested.
- Contact support@brandfolder.com to complete the configuration.