Limiting portal access by group in multi-forest ADFS


have multi-forest deployment of adfs office 365. trying control access office 365 portal through adfs claim rules using security groups decided here: https://technet.microsoft.com/en-us/library/dn592182.aspx 

able create rule blocks access office 365 portal using groupsid of security group exists in same forest adfs farm (forest  a). however, when try use groupsid of security group in other forest (forest b), rule not work. have 2 way trust set between forest , forest b, , users in both forests able authenticate office 365 using upn. able use security groups in forest b manage access o365. can tell me how make happen?

ps: know strange scenario, have in fact been asked turn off o365 portal group of users... 

hi,
posting in directory services  forums. since issue related adfs, suggest post question in adfs forum:

https://social.technet.microsoft.com/forums/windowsserver/en-us/home?forum=adfs

the reason why recommend posting appropriately qualified pool of respondents, , other partners read forums regularly can either share knowledge or learn interaction us. thank understanding.
regards,
wendy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS