Active Directory Federation Services
Security Requirements and Controls
Change identity providers
permission
ADFS is a software component from Microsoft that runs on Windows. It can provide users with single sign-on access to LogScale.
Important
For Cloud customers, please gather the information on Authentication & Identity Providers, and contact Support, and they can work with you to setup your chosen IdP service.
To configure the ADFS for integration with LogScale:
First add a new Relying Party Trust. Click Start then select Enter data about the relying party manually and click .
In the Configure URL tab, enable support for the SAML 2.0 WebSSO protocol. Use
http(s)://$YOUR_LOGSCALE_URL/api/v1/saml/acs
In the Configure Identifiers tab, add
http(s)://$YOUR_LOGSCALE_URL/api/v1/saml/metadata
. In the last tab, make sure to check Configure claims issuance policy for this application.In the new pop-up, add a rule with the rule type, Send LDAP Attributes as Claims. In the table on the left side (LDAP attribute), select Email Addresses. Then, in the table on the right side (Outgoing claim type), select Name ID.
Now, add another rule, also with the rule type, Send LDAP Attributes as Claims. In the table on the left side (LDAP attribute), select Is-Member-of:DL. In the table on the right side (Outgoing claim type), select Group.
You will need to find the metadata XML at this URL, adjusting the domain address to your domain:
https://<ADFSURL_PUBLIC_URL>/FederationMetadata/2007-06/FederationMetadata.xml>
You will also need the
entityId
asIdp Entity Id
, as well as the<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
asSign on URL
, andX509Certificate
asCertificate in Base 64
If you have a self-hosted installation of LogScale, you need to save the certificate as a PEM file on the server.
To use SAML with LogScale Cloud, go to the Authentication & Identity Providers documentation page.
See the Active Directory FS Documentation for more information.