Example Scenario: Access Manager as the Claims Provider and AD FS 2.0 as the Relying Party

Accessing the WIF Sample Application

In this scenario, John from Example.com accesses the Contoso WIF sample application.

NOTE:Clear all cookies in the Internet Explorer on the AD FS 2.0 computer (fsweb.contoso.com). To clear cookies, click Tools > Internet Options > Delete under Browsing History, and then select cookies for deletion.

  1. On the AD FS 2.0 computer, open a browser window, then navigate to https://fsweb.contoso.com/ClaimsAwareWebAppWithManagedSTS/default.aspx.

    The first page prompts you to select your organization from a list.

  2. Select NAM Example, then click Continue to sign in.

    When only one Identity Provider is available, AD FS 2.0 forwards the request to that Identity Provider by default.

  3. The NAM login page appears. Type the user name john, type the password test, then click Login.

Accessing the SharePoint 2010 Application

The user's email ID is used as the mapped attribute to access the SharePoint 2010 application. Assume that a user is created in Access Manager Identity Server. The email ID configured for this user is namuser1@namidp.com.

NOTE:Clear all cookies in the Internet Explorer on the AD FS 2.0 computer (fsweb.contoso.com). Click Tools > Internet Options > Delete under Browsing History, then select cookies for deletion.

  1. Ensure that an email ID has been configured for the user in the Access Manager user store.

    For this example, use namuser1@namidp.com.

  2. Access the SharePoint 2010 application. The user is redirected to AD FS 2.0.

  3. Select NetIQ Identity Server. The user is redirected to the Access Manager Identity Server nidp page for authentication.

  4. Provide namuser1 as the username and password. After authentication, the user is redirected to the SharePoint application.