Complete the following to map an HTML form adapter instance.
- On the Authentication Source Mapping tab, click Map New Adapter Instance.
- On the Adapter instance tab, in the Adapter Instance list, select the HTML Form Adapter instance that you created in Configuring an IdP adapter. Click Next.
- On the Virtual Server IDs tab, if you have a single domain, click Next.
-
If you configured virtual server IDs on the General Info
tab of the connection and have a separate HTML Form Adapter instances for each
subdomain:
- Select the Restrict Virtual Server IDs check box.
- Select the check box for the virtual server ID that represents the subdomain associated with this HTML Form Adapter instance.
- Click Next.
-
If you configured virtual server IDs on the General Info
tab of the connection and use a single HTML Form Adapter instances for all
subdomains:
- Leave the Restrict Virtual Server IDs check box unselected. Click Next.
- (Recommended) When you reach the Issuance Criteria tab later in the setup process, create an OGNL expression to protect against unauthorized access.
- On the Mapping Method tab, select Retrieve additional attributes from multiple data stores using one mapping. Click Next.
- On the Attribute Sources & User Lookup tab, complete the steps in Configuring attribute source and user lookup for HTML Form Adapter instances, and then click Next.
-
On the Attribute Contract Fulfillment tab, create the
following mappings, and then click Next.
Attribute Contract Source Value ImmutableID
LDAP (<Your datastore>)
objectGUID
SAML_SUBJECT
LDAP (<Your datastore>)
objectGUID
UPN
LDAP (<Your datastore>) userPrincipalName
SAML_NAME_FORMAT
Text
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
-
If you use a single HTML Form Adapter instance for users in multiple
subdomains, on the Issuance Criteria tab, create an OGNL
expression verify the virtual server ID and other conditions, such as group
membership.
Note:
For help with OGNL expressions, see Defining issuance criteria for IdP Browser SSO, Enabling and disabling expressions and Constructing OGNL expressions in the PingFederate documentation.
- Click Next
- On the Summary tab, click Done.