Configuring objectSid as the Immutable ID consists of the following tasks:
Adding the objectSid Attribute as a Custom Attribute
Creating Attribute Set
Configuring the Attribute Set for WS-Federation or WS-Trust
On the Home page, click Identity Servers > [cluster name] > IDP Global Settings > Custom Attributes.
Under LDAP Attribute Names, click Plus icon.
Specify objectSid, and select 64-bit Encode Attribute Data.
Click Save.
On the Home page, click Identity Servers > [cluster name] > IDP Global Settings > Attribute Sets.
Click Plus icon, and specify a Set Name. Click Next.
Click Plus icon and specify the following details:
Field |
Description |
---|---|
Local Attribute |
Ldap Attribute:mail [LDAP Attribute Profile] |
Remote Attribute |
URN |
Remote Namespace |
http://schemas.xmlsoap.org/claims |
Remote Format |
unspecified |
Attribute Value Encoding |
Special characters encoded |
Click Save.
Create another Attribute Set. Click Plus icon, and specify a Set Name.
Click Next > Plus icon and specify the following details:
Field |
Description |
---|---|
Local Attribute |
Ldap Attribute: Ldap Attribute:objectSid#[nidsForceBinary] [LDAP Attribute Profile] |
Remote Attribute |
ImmutableID |
Remote Namespace |
http://schemas.microsoft.com/LiveID/Federation/2008/05 |
Remote Format |
unspecified |
Attribute value encoding |
Special characters encoded |
Click Save > Finish.
Configure the Attribute Set for the WS-Federation or WS-Trust service provider. See Configuring the Attributes Set with Authentication and Modifying Service Providers.