Map an IdP adapter
Steps
-
Click Map New Adapter Instance and select the HTML Form IdP Adapter as the Adapter Instance.
-
On the Assertion Mapping screen, select the option button to retrieve additional attributes from a data store including options to use alternate data stores and/or a failsafe mapping.
-
Click Add Attribute Source and configure the LDAP data source, adding
userPrincipalName
as an additional attribute and including a filter value such assAMAccountName=${username}
. -
On the Attribute Contract Fulfillment screen, select Text as the Source for SAML_SUBJECT and enter an unused value. Select LDAP as the Source for upn and select userPrincipalName as the value.
-
On the Failsafe Attribute Source screen, select the Abort the SSO Transaction option.