Adding a relying party trust for Arctera Insight Archiving
The first step to configure your AD FS environment is to add a relying party trust for Arctera Insight Archiving.
Note: We recommend that you do not change the Index Value of the Endpoint from its default value. Changing the Index Value of the Endpoint can prevent the Arctera Insight Archiving authentication service from working properly with your AD FS environment.
To add a relying party trust for Arctera Insight Archiving
-
Access the AD FS Management console.
-
In the left pane of the AD FS Management console, expand Trust Relationships, right-clickRelying Party Trusts, and then clickAdd Relying Party Trust.
-
In the Welcomepanel of the Add Relying Party Trust Wizard, clickStart.
-
In the Select Data Sourcepanel, selectEnter data about the relying party manually, and then clickNext.
-
In the Specify Display Namepanel, enter**
Cloud Archivein theDisplay Namefield, and then clickNext**. -
In the Choose Profilepanel, select a profile, and then clickNext.
-
In the Configure Certificatepanel, clickNext to skip this optional step.Note: We recommend that you do not configure a certificate. Configuring a certificate prevents the Arctera Insight Archiving authentication service from working properly with your AD FS environment.
-
In the Configure URLpanel, selectEnable support for the SAML 2.0 WebSSO protocol.
-
In the Configure URLpanel, enter the Entity ID from theYour Trust Informationsection on theAuthentication Managementpage of Arctera Insight Management Console in theRelying party SAML 2.0 SSO service URLfield, and then clickNext.Note: The Entity ID varies based on the location of your organization. If you cannot find the Entity ID for your organization, contactArctera Services & Support.
-
In the Configure Identifierspanel, enter the Entity ID again in theRelying party trust identifierfield, clickAddto add the identifier, and then clickNext.
-
For AD FS 3.0 only, in the Configure Multi-factor Authentication Now?panel, selectI do not want to configure multi-factor authentication settings for this relying party trust at this time, and then clickNext.
-
In the Choose Issuance Authorization Rulespanel, selectPermit all users to access this relying party, and then clickNext.
-
In the Ready to Add Trustpanel, review the configured settings, and then clickNext.
-
In the Finishpanel, selectOpen the Edit Claim Rules dialog for this relying party trust when the wizard closes, and then clickClose.
-
In the Edit Claim Rules for Cloud Archivewindow, clickAdd Rule.
-
In the Select Rule Templatepanel of the Add Transform Claim Rule Wizard, selectSend LDAP Attributes as Claimsin theClaim rule templatefield, and then clickNext.
-
In the Configure Rulepanel, enter**
Send Claims to Cloud Archivein theClaim rule name** section. -
In the Configure Rulepanel, selectActive Directoryin theAttribute store section.
-
In the Configure Rulepanel, select the following sets of LDAP attributes and outgoing claim types in theMapping of LDAP attributes to outgoing claim types section.
LDAP attribute Outgoing claim type E-Mail-Addresses E-Mail Address Given-Name Given Name Surname Surname -
In the Configure Rulepanel, clickFinishto close theAdd Transform Claim Rule Wizard.
-
In the Edit Claim Rules for Cloud Archivewindow, clickOK to close the window.
-
In the AD FS Management Console, select Cloud Archivein theRelying Party Trusts pane.
-
In the Cloud Archivesection of theActionspane, clickProperties.
-
In the Cloud Archive Propertieswindow, select theAdvanced tab.
-
In the Secure hash algorithm field, select one of the following algorithms:
-
SHA-1
-
SHA-256Note: We recommend that you select the SHA-1 algorithm.
-
-
Click OKto close theCloud Archive Properties window.
Related information