Active Directory Federation Services (AD FS) provides support for claims-aware identity solutions that involve Windows Server and Active Directory technology. AD FS supports the WS-Trust, WS-Federation, and Security Assertion Markup Language (SAML) protocols.
This section uses Windows 2016 as an example to describe how to configure AD FS as a SAML server to work with Trend Micro Email Security. Make sure you have installed AD FS successfully.
- Go to .
- On the AD FS management console, go to AD FS, right-click Relying Party Trusts, and then choose Add Relying Party Trust.
-
Complete settings for each screen in the Add Relying Party
Trust wizard.
- From the Edit Claim Issuance Policy for Trend Micro Email Security Administrator Console dialog box, click Add Rule in the Issuance Transform Rules tab.
-
Complete settings for each screen in the Add Transform
Claim Rule wizard.
-
From
, double-click the relying party trust file you created
earlier.
- From the Test Properties dialog box, click the Advanced tab.
- Select SHA1 from the Secure hash algorithm drop-down list and click OK.
-
Collect the single sign-on logon and logoff URLs and
obtain a certificate for signature validation from AD FS.