Introduction
Springboard support authentication with any SAML 2.0 compliant service. This documentation has been written on the assumption that you are using ADFS. If you are using a different authentication provider, please request the required documentation from PeopleScout.
The steps required to configure Springboard to authenticate against your ADFS server are outlined below;
Assumptions
The following documentation assumes that you have the following in place;
• Active Directory Domain,
• Domain Controller (or separate server) with AD FS role enabled,
• Domain Administrator privileges,
• A Universal Active Directory Security Group to grant access to Springboard.
Prerequisites
Before commencing the steps below please ensure you have;
• Provided PeopleScout with your careers site URL e.g https://careers.mycompany.com
• The Metadata.xml file (provided by PeopleScout)
Dependencies
At the completion of this document you will have;
• Set up a Relying Party Trust
• Edited the claim rules
• Generated a Token Signing Certificate (Must provide to PeopleScout)
Create a Relying Party Trust
1. Log into your AD FS server and open the AD FS Management Console
2. Expand Trust Relationships
3. To launch the Relying Party Trust wizard, Right click Relying Part Trust and select Add Relying Party Trust…
4. Select Start to begin the Wizard.
5. Select Import data about the relying part from a file
6. Select browse and select the XML file provided to you by PeopleScout
7. Give the trust a name and description to help you identify it later.
8. Choose whether to require users to use multi-factor authentication. In this example we will assume you select “I do not want to configure multi-factor authentication…”
9. Select Permit all users to access this relying party
10. Select Next to accept the Trust
11. Select Close to finish the wizard and open the rules editor
Editing Claim Rules
12. Select Add Rule…
13. Select the Send LDAP Attributes as Claims, then select Next
14. Name the rule Send UPN
15. Select Active Directory as the Attribute Store
16. Select User-Principal-Name and UPN as the claim types
17. Select Finish
18. Select Add Rule
19. Select Transform an Incoming Claim
20. Select Next
21. Name the claim rule tx Claims
22. Incoming claim type = UPN
23. Outgoing claim type = Name ID
24. Outgoing name ID format = Transient Identifier
25. Pass through all claim values
26. Select Finish
27. Select Add Rule…
28. Select Send Group Membership as a Claim
29. Select Next
30. Name the rule Send SpringboardUser Role
31. Select the Active Directory Security group used to authenticate users
32. Outgoing claim type = Role
33. Outgoing claim value = SpringboardUser
34. Select Finish
35. Select Add Rule…
36. Select Send Claims Using a Custom Rule
37. Select Next
38. Name the Rule RASP_ORG_ID
39. Custom Rule =
=> issue(Type = "RASP_ORG_ID", Value = "XXXXX");
40. Select Finish
41. Your rules editor should now look like the image below
42. Generate and send PeopleScout a Token-Signing Certificate to import into Springboard to finish the trust. Information is available from Microsoft here;