> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-feat-poc-api-playground.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML: ADFS Configuration

> This document provides instructions for creating an application within ADFS for compatibility with BloodHound Enterprise.

<img noZoom src="https://mintcdn.com/specterops-feat-poc-api-playground/5XJ7p5p7xL9ZwxE2/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=5XJ7p5p7xL9ZwxE2&q=85&s=79b8dea14cb2266671c0a2f64f4b9caa" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

For general instructions on adding a SAML provider to BloodHound Enterprise or for configuring users to utilize a SAML provider, see [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml).

See [SAML Order of Operations and Quick Reference](/manage-bloodhound/auth/saml) before starting.

## Create an Application

1. In the AD FS management console, right-click on Relaying Party Trust and click “Add Relaying Party Trust”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-25.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=119560e61e8041efd75271e26c850fd8" width="936" height="478" data-path="assets/image-2-25.png" />
</Frame>

2. Choose “Claims aware” and click “Start”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-26.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=da05cdcf2ae534a5a48274605ee23149" width="936" height="762" data-path="assets/image-2-26.png" />
</Frame>

3. Insert the metadata URL based on your chosen name and click “Next.”

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-27.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=b1bf41f4f5d446269dafd0fbded56c7a" width="936" height="762" data-path="assets/image-2-27.png" />
</Frame>

4. Enter the preferred display name and click “Next.”

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-28.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=1192e44f214eb38db8003392e8c5568f" width="936" height="762" data-path="assets/image-2-28.png" />
</Frame>

5. Choose the desired Access Control Policy. (Note that access and permissions are configured within BloodHound Enterprise).

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-29.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=b15e09e07a613c92909b316d65c15998" width="936" height="762" data-path="assets/image-2-29.png" />
</Frame>

6. Review the information presented and click “Next”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-30.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=106908619107b7d2cac371784f70219e" width="936" height="762" data-path="assets/image-2-30.png" />
</Frame>

7. Leave the “Configure claims issuance policy for this application” box checked and click “Close”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-31.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=74b7ffa39080b6c41a20098c709eeabc" width="936" height="762" data-path="assets/image-2-31.png" />
</Frame>

## Complete SAML Integration Configuration

1. On the “Edit Claim Issuance Policy” dialog box, click “Add Rule…”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-32.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=53d3705db812bee44d385e3cc4e41354" width="936" height="1046" data-path="assets/image-2-32.png" />
</Frame>

2. Choose “Send LDAP Attributes as Claims” and click “Next.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-33.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=fa034e77e0339d73df483034f18c81b7" width="936" height="762" data-path="assets/image-2-33.png" />
</Frame>

3. Fill out the following and click “Finish”.

   LDAP Attribute: E-Mail-Addresses
   Outgoing Claim Type : E-Mail Address

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-34.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=931fa1a6e630c31036ce763a0273b33a" width="936" height="762" data-path="assets/image-2-34.png" />
</Frame>

4. Click “Add Rule” to add another claim rule.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-35.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=5663b2958e96ca31099709bc1c6062f1" width="936" height="1046" data-path="assets/image-2-35.png" />
</Frame>

5. Choose “Transform and Incoming Claim” and click “Next”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-36.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=28060e47cdf94ddd0f993c4510c5b104" width="936" height="762" data-path="assets/image-2-36.png" />
</Frame>

6. Fill out the following and click “Finish”.

   Incoming claim type: E-Mail Address
   Outgoing claim type: Name ID
   Outgoing name ID format: Email
   Choose “Pass through all claim values”

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-37.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=626ef24768dfdaf1d8a4fed3f382c4ad" width="936" height="762" data-path="assets/image-2-37.png" />
</Frame>

7. Click “Apply”.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/WAePk2ssimS390wS/assets/image-2-38.png?fit=max&auto=format&n=WAePk2ssimS390wS&q=85&s=8bed68441bfd293468a37da2512726a0" width="936" height="1046" data-path="assets/image-2-38.png" />
</Frame>

8. Download the metadata file provided by your ADFS environment. By default, this is hosted at: [https://YOURDOMAIN/federationmetadata/2007-06/federationmetadata.xml](https://YOURDOMAIN/federationmetadata/2007-06/federationmetadata.xml)
9. Follow the instructions at [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml) to create the SAML provider in BloodHound Enterprise.
