Monday, December 14, 2015

AAD : The default WS-Federation claims

I have an ASP.NET RP using OWIN WS-Fed to talk to an ADFS instance and this ADFS instance has Azure AD as a CP.

For reference, this is the default claims set from AAD:

Claims from ClaimsIdentity

Claim Type Claim Value QY7TN_h.....vFbw9IKD-nY 4ef13bb.....a8291aeded 8f803ba.........63-eacba54 joe joe bloggs Mozilla/5.0 (Windows NT 6.3; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0 /adfs/ls/ true 0000.....0-0080e7 https://my-pc/WebApp-ADFS-DotNet/ 2015-12-13T19:12:58.920Z

Sadly, there is no way currently to alter this default set other than to use Microsoft Graph to get the claims yourself.

Note that because AAD is built on a Graph platform, a lot of the values are actually GUID's.


No comments: