Highlighted

Using User Principal Name instead of email address for MS ADFS federation SSO

New Here ,
Oct 30, 2019

Copy link to clipboard

Copied

We have two AD groups, Staff and Students, one, Staff has on-prem email and the Active Directory emailaddress field is populated; the other, Students, has O365 email addresses and consequently they emailaddress field in AD is not populated. Therefore, to add Students to the Adobe Admin Console as users and use MS ADFS, we want to change the settings for authenticaiton from "emailaddress => emailaddress" to "User Principal Name => emailaddress" . Both AD groups have values that match the email format and will work but we are not getting any help from Chat not Expert sessions: they state why it is not working with Students not how to reconfigure it to use UPNs.

Does anyone have any experience with this? 

 

Hi,

Yes, this can be done by creating a custom Rule to set username instead of email as the login method in the directory config. Steps can be found in this document. See also https://helpx.adobe.com/ie/enterprise/kb/configure-microsoft-ad-fs-with-sso.html

 

 

 

Topics

Identity and SSO, Troubleshooting

Views

725

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more

Using User Principal Name instead of email address for MS ADFS federation SSO

New Here ,
Oct 30, 2019

Copy link to clipboard

Copied

We have two AD groups, Staff and Students, one, Staff has on-prem email and the Active Directory emailaddress field is populated; the other, Students, has O365 email addresses and consequently they emailaddress field in AD is not populated. Therefore, to add Students to the Adobe Admin Console as users and use MS ADFS, we want to change the settings for authenticaiton from "emailaddress => emailaddress" to "User Principal Name => emailaddress" . Both AD groups have values that match the email format and will work but we are not getting any help from Chat not Expert sessions: they state why it is not working with Students not how to reconfigure it to use UPNs.

Does anyone have any experience with this? 

 

Hi,

Yes, this can be done by creating a custom Rule to set username instead of email as the login method in the directory config. Steps can be found in this document. See also https://helpx.adobe.com/ie/enterprise/kb/configure-microsoft-ad-fs-with-sso.html

 

 

 

Topics

Identity and SSO, Troubleshooting

Views

726

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
Adobe Employee ,
Nov 04, 2019

Copy link to clipboard

Copied

Hi,

Yes, this can be done by creating a custom Rule to set username instead of email as the login method in the directory config. Steps can be found in this document. See also https://helpx.adobe.com/ie/enterprise/kb/configure-microsoft-ad-fs-with-sso.html

 

 

 

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
Reply
Loading...
New Here ,
Nov 07, 2019

Copy link to clipboard

Copied

Alister, thank  you for your how-to it was just what we needed. Why, pray tell, were the Adobe support staff unable to provide guidance when asked? ( rhetorical question, no answer expected)

 

Likes

Translate

Translate

Report

Report
Community Guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
Reply
Loading...