Setting Up Roles for ClaimApp and TokenApp Claims

When users access resources on the ADFS server, they need to have two roles assigned: a ClaimApp role and a TokenApp role. The following steps explain how to create these two roles so that they are assigned to all users that log in to Identity Server.

  1. Click Devices > Identity Servers > Servers > Edit > Roles > Manage Policies.

  2. Click New, specify a name for the policy, select Identity Server: Roles, and click OK.

  3. On the Rule 1 page, leave Condition Group 1 blank.

    With no conditions to match, this rule matches all authenticated users.

  4. In the Actions section, click New > Activate Role.

  5. Specify ClaimApp.

  6. In the Actions section, click New > Activate Role.

  7. Specify TokenApp.

  8. Click OK > OK.

  9. Click Apply Changes.

  10. Click Close.

  11. On the Roles page, select the role policy you just created, then click Enable.

  12. Click OK.

  13. Update Identity Server.

  14. Continue with Importing the ADFS Signing Certificate into the NIDP-Truststore.