SAP Knowledge Base Article - Public

3242305 - Configuring SSO with Microsoft Active Directory Federation Services (ADFS)

Symptom

We want to configure the SAML-integration with our ADFS. Which instructions do we have to follow?

Resolution

  1. Add a new Relying Party Trust in your ADFS
  2. Import Process Manager metadata. You can download the metadata directly from the Process Manager Explorer under Setup > SAP Signavio Collaboration Hub Authentication > Download the SAML service provider metadata.
  3. Create a new outgoing claim rule that sends LDAP attributes as claims. For this purpose, map the following outgoing claim types to the LDAP attribute.
    LDAP-AttributeOutgoing Claim TypeGiven Name
    Given Namefirst_name
    Surnamelast_name
    E-Mail Addressesemail
    SAM-Account-NameName ID (from the drop-down menu
  4. As described in our user manual, please add the SAML metadata from your ADFS to the metadata field in the Process Manager.
  5. Please note that your request must be signed in ADFS with "Sign authentication request".
  6. Once the configuration on both sides has been completed, you can test the SSO via this URL (Please choose the appropriate infrastructure for your link)
    https://<Signavio Instance>.signavio.com/p/hub?t=<Your workspace ID>

Keywords

sap signavio, saml, sso, configuration, adfs, Microsoft Active Directory Federation Services , KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , How To

Product

SAP Signavio Process Manager all versions ; Signavio Process Manager all versions