Our client has setup ADFS to send over a group as a role claim but i could not find this group with c:0-.t|xxx in our environment but i can find it with i:05.t|xxx. Somehow if i granted permission through I:05.t| the users in this group does not get the
appropriate permission. And it is mentioned that we have to resolved the group by c:0-t|xx in order to grant correctly. Whatelse is missing on Sharepoint configuration. (Web app Authetication has been set to grant access to allow Trusted Identity Provider)
My ADFS team says they have already seen the role claim being passed in (i do not know how to verify) and the below are the configuration on my sharepoint. Can you advice if the setup are complete on sharepoint portion?
ProviderUri : https://adfs.global.com/adfs/ls
DefaultProviderRealm : urn:sharepoint:SiteA-ext.wilhelmsen.com
ProviderRealms : {}
ClaimTypes : {http://schemas.xmlsoap.org/ws/2005/05/identity
/claims/emailaddress, http://schemas.xmlsoap.or
g/ws/2005/05/identity/claims/upn, http://schema
s.microsoft.com/ws/2008/06/identity/claims/role
, http://schemas.microsoft.com/ws/2008/06/ident
ity/claims/primarysid}
HasClaimTypeInformation : True
ClaimTypeInformation : {EmailAddress, UPN, Role, SID}
ClaimProviderName :
UseWReplyParameter : False
UseWHomeRealmParameter : False
RegisteredIssuerName :
IdentityClaimTypeInformation : Microsoft.SharePoint.Administration.Claims.SPTr
ustedClaimTypeInformation
Description : Let client to access Site A
SigningCertificate : [Subject]
CN=adfs.global.com, OU=xx, o=xx
nx, L=North, S=Baru
m, C=NO
[Issuer]
CN=cert, OU
=Terms of use at https://www.verisign.com/rpa (
c)123, OU=VeriSign Trust Network, O="VeriSign, I
nc.", C=US
[Serial Number]
3ejri3n4ik400000000000
[Not Before]
02.11.2010 01:00:00
[Not After]
02.11.2019 00:59:59
[Thumbprint]
Etrts33566777899900000
AdditionalSigningCertificates : {}
MetadataEndPoint :
IsAutomaticallyUpdated : False
Name : SiteA Access
TypeName : Microsoft.SharePoint.Administration.Claims.SPTr
ustedLoginProvider
DisplayName : SiteA Access
Id : erert3445-ervtte-4013-80e9-55b4041d9003
Status : Online
Parent : SPSecurityTokenServiceManager Name=SecurityToke
nServiceManager
Version : 12345546
Properties : {}
Farm : SPFarm Name=DERSDFR_Config
UpgradedPersistedProperties : {}