---
url: >-
  https://flip-chart.ru/developers/en/on-premise/installation/other/adfs/adfs-saml.md
description: >-
  Configure a relying party trust and claim issuance rules in ADFS for SAML
  sign-in to flip on-premise, then complete the integration in the flip SSO
  settings.
---

# Configuring a relying party trust in ADFS for flip integration

## Step 1: Open the ADFS management console

Open **AD FS Management**.\
![1](/on-premise/images/adfs/saml/adfs-saml-1.png)

## Step 2: Create a relying party trust

Go to **Relying Party Trusts** → select **Add Relying Party Trust...**\
![2](/on-premise/images/adfs/saml/adfs-saml-2.png)

### In the *Add Relying Party Trust Wizard*, complete the following steps:

1. Select the type:\
   **Claims aware** → **Start**\
   ![3](/on-premise/images/adfs/saml/adfs-saml-3.png)

2. Setup method:\
   **Enter data about the relying party manually** → **Next >**\
   ![4](/on-premise/images/adfs/saml/adfs-saml-4.png)

3. Enter a display name for the relying party trust, for example:\
   `Flip-applications-SAML` → **Next >**\
   ![5](/on-premise/images/adfs/saml/adfs-saml-5.png)

4. Skip the optional encryption setup step by clicking **Next >**\
   ![6](/on-premise/images/adfs/saml/adfs-saml-6.png)

5. Enable SAML 2.0 support:\
   Select the **Enable support for the SAML 2.0 WebSSO protocol** check box\
   and enter the application's ACS URL in the following format:\
   `https://example.flip-chart.ru/app/api/v1/auth/saml/acs`\
   ![7](/on-premise/images/adfs/saml/adfs-saml-7.png)

6. Enter the relying party trust identifier in the following format:\
   `https://example.flip-chart.ru/app/` → **Add** → **Next >**\
   ![8](/on-premise/images/adfs/saml/adfs-saml-8.png)

7. Set up an additional level of user access (**Choose Access Control Policy**) → **Next >**\
   ![9](/on-premise/images/adfs/saml/adfs-saml-9.png)

8. Confirm adding the relying party trust → **Next >**\
   ![10](/on-premise/images/adfs/saml/adfs-saml-10.png)

9. Finish creating the relying party trust for the flip integration → **Close**\
   ![11](/on-premise/images/adfs/saml/adfs-saml-11.png)

## Step 3: Configure the claim rules

After the relying party trust is created, select it and click **Edit Claim Issuance Policy...** → in the window that opens, click **Add Rule...**

![12](/on-premise/images/adfs/saml/adfs-saml-12.png)\
![13](/on-premise/images/adfs/saml/adfs-saml-13.png)

### Rule 1: Issue a transient NameID

For the rule template, select:\
**Claim rule template**: `Transform an Incoming Claim`\
![14](/on-premise/images/adfs/saml/adfs-saml-14.png)

#### Fill in the claim rule fields:

![15](/on-premise/images/adfs/saml/adfs-saml-15.png)\
**Claim rule name**: `Issue transient NameID`\
**Incoming claim type**: `Windows account name`\
**Outgoing claim type**: `Name ID`\
**Outgoing name ID format**: `Transient Identifier`\
**Pass through all claim values**

### Rule 2: Send LDAP attributes as claims

Click **Add Rule...** to add the second claim rule\
![16](/on-premise/images/adfs/saml/adfs-saml-16.png)

For the rule template, select:\
**Claim rule template**: `Send LDAP Attributes as Claims`\
![17](/on-premise/images/adfs/saml/adfs-saml-17.png)

#### Fill in the claim rule fields:

![18](/on-premise/images/adfs/saml/adfs-saml-18.png)\
**Claim rule name**: `Send LDAP Attributes as Claims`\
**Attribute store**: `Active Directory`\
**Mappings**:

* `User-Principal-Name` → `email`
* `User-Principal-Name` → `username`

Click **Finish** to create the rule\
![19](/on-premise/images/adfs/saml/adfs-saml-19.png)

Once created, the rules should be listed in the claim issuance policy window.\
Click **Apply** → **OK** to apply and save the rules.

## Step 4: Complete the integration on the SSO page using the data you obtained

### Go to the [SSO](/en/on-premise/installation/other/sso) integration settings page

#### Fill in the fields as follows:

* **Protocol**: `SAML 2.0`
* **Identity provider metadata URL**:\
  `https://adfs.example.ru/FederationMetadata/2007-06/FederationMetadata.xml`
* **Verification certificate**: the certificate data from the metadata page
* **Identity provider issuer**:\
  `https://example.flip-chart.ru/app/`

![20](/on-premise/images/adfs/saml/adfs-saml-20.png)
