Voor MFA voor diensten achter SURFconext in combinatie met ADFS moet het attribuut http://schemas.microsoft.com/claims/authnmethodsreferences vrijgegevem worden aan SURFconext. Zo stel je dit in in de bestaande ADFS-configuratie:
- Ga naar Relying Party Trusts.
- Rechter muisklik op SURFconext.
- Selecteer Edit Claim Issuance Policy.
- Klik op Add Rule.
- Selecteer Transform an Incoming claim.
- Voer een naam in, bijvoorbeeld 'AuthnMethodsReferences'
- Voor incoming en outgoing claim type, selecteer Authentication Methods References.
- Vink Pass trough all claim values aan.
- Klik op OK.
Testen of dit goed ingeteld is:
- Ga naar https://engine.test.surfconext.nl/authentication/sp/debug (als de IdP gekoppeld is aan SURFconext TEST) of https://engine.surfconext.nl/authentication/sp/debug (voor SURFconext productie) te gaan
- Log in met de IdP.
- In het overzicht van claims zie je of
http://schemas.microsoft.com/claims/authnmethodsreferences" nu inderdaad vrijgegeven wordt.
Overview
Content Tools
