Adding a relying party trust for Arctera Unified Platform
The first step to configure your AD FS environment is to add a relying party trust for Arctera Unified Platform.
Note: We recommend that you do not change the Index Value of the Endpoint from its default value. Changing the Index Value of the Endpoint can prevent the Arctera Unified Platform authentication service from working properly with your AD FS environment.
To add a relying party trust for Arctera Unified Platform
-
Access the AD FS Management console.
-
In the left pane of the AD FS Management console, expand Trust Relationships, right-click** Relying Party Trusts , and then click Add Relying Party Trust**.
-
In the Welcome panel of the Add Relying Party Trust Wizard, clickStart.
-
In the Select Data Source panel, selectEnter data about the relying party manually, and then click** Next**.
-
In the **Specify Display Name panel, enter
Cloud Archive**in the Display Name field, and then click Next. -
In the Choose Profile panel, select a profile, and then clickNext.
-
In the Configure Certificate panel, clickNext to skip this optional step.Note: We recommend that you do not configure a certificate. Configuring a certificate prevents the Arctera Unified Platform authentication service from working properly with your AD FS environment.
-
In the Configure URL panel, selectEnable support for the SAML 2.0 WebSSO protocol.
-
In the Configure URL panel, enter the Entity ID from theYour Trust Information section on theAuthentication Management page of Arctera Management Console in theRelying party SAML 2.0 SSO service URL field, and then clickNext.Note: The Entity ID varies based on the location of your organization. If you cannot find the Entity ID for your organization, contactArctera Services & Support.
-
In the Configure Identifiers panel, enter the Entity ID again in theRelying party trust identifier field, clickAdd to add the identifier, and then clickNext.
-
For AD FS 3.0 only, in the Configure Multi-factor Authentication Now?panel, select I do not want to configure multi-factor authentication settings for this relying party trust at this time, and then click Next.
-
In the Choose Issuance Authorization Rules panel, selectPermit all users to access this relying party, and then click** Next**.
-
In the Ready to Add Trust panel, review the configured settings, and then clickNext.
-
In the Finish panel, selectOpen the Edit Claim Rules dialog for this relying party trust when the wizard closes, and then click** Close**.
-
In the Edit Claim Rules for Cloud Archive window, clickAdd Rule.
-
In the Select Rule Template panel of the Add Transform Claim Rule Wizard, selectSend LDAP Attributes as Claims in theClaim rule template field, and then clickNext.
-
In the **Configure Rule panel, enter
Send Claims to Cloud Archive**in the Claim rule name section. -
In the Configure Rule panel, selectActive Directory in theAttribute store section.
-
In the Configure Rule panel, select the following sets of LDAP attributes and outgoing claim types in theMapping of LDAP attributes to outgoing claim types section.
LDAP attribute Outgoing claim type E-Mail-Addresses E-Mail Address Given-Name Given Name Surname Surname -
In the Configure Rule panel, clickFinish to close theAdd Transform Claim Rule Wizard.
-
In the Edit Claim Rules for Cloud Archive window, clickOK to close the window.
-
In the AD FS Management Console, select Cloud Archive in theRelying Party Trusts pane.
-
In the Cloud Archive section of theActions pane, clickProperties.
-
In the Cloud Archive Properties window, select theAdvanced tab.
-
In the Secure hash algorithm field, select one of the following algorithms:
-
SHA-1
-
SHA-256Note: We recommend that you select the SHA-1 algorithm.
-
-
Click OK to close theCloud Archive Properties window.
Related information