Skip to main content

Claim Rules

After a user is authenticated, AD FS claim rules specify the data attributes and format that will be sent to HMP in the SAML response. The Edit Claim Rules wizard has three panes:

Issuance Transform Rules

Since HMP requires a User Principal Name element, you need to create a rule that extracts the user's UPN (i.e. the user's Windows Account Name) from Active Directory. The Issuance Transform Rules pane allows you to do this. See the following section for details.

Issuance Authorization Rules

You can establish custom access rules (whitelist/blacklist) under Issuance Authorization Rules.

Delegation Authorization Rules

The Delegation Authorization Rules pane is not used for HMP SSO.

Create an Issuance Transform Rule for the UPN Element

  1. On the Issuance Transform Rules pane, click Add Rule.
  2. Under Claim rule template, choose Pass Through or Filter an Incoming Claim.
  3. Click Next to continue. Give the claim rule a name, and choose UPN from the Incoming claim type list, and specify any necessary pass through values.
  4. Click Finish.
  5. Click Apply, then OK.

You should see the new Relying Party Trust in the main window of the AD FS snap-in. Note that you can make changes to the Claim Rules for that trust or its Properties by right-clicking:

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.