Enabling Email as a Claim Type

You can enable three types of claims for identity that can be enabled on an ADFS server. The claims include Common Name, Email, and User Principal Name. The ADFS step-by-step guide specifies that you do everything with a User Principal Name, which is an Active Directory convention. Although it could be given an email name that looks the same, it is not. This scenario selects to use Email instead of Common Name because Email is a more common configuration.

  1. From the Administrative Tools, open the Active Directory Federation Services tool.

  2. Navigate to Organizational Claims by clicking Federation Service > Trust Policy > My Organization.

  3. Verify that Email is in this list. If it is not, move it to the list.

  4. Navigate to your Token-based Application and enable email by right-clicking the application, editing the properties, and selecting Enabled.

  5. Navigate to your Claims-aware Application and repeat the process.

  6. Continue with Creating an Account Partners Configuration.