# How to configure Microsoft ADFS SSO for Swarmica 
# Resolution

You will need to provide the Swarmica representative with following information

*   The address of your ADFS server. Example `adfs.example.com`
*   Client Identifier for the Swarmica application group. Example `51cf596b-ac85-4d45-988b-2689cc45281f`
*   Relying Party ID. Note that if you didn't change it manually it can be identical to client identifier. Example `51cf596b-ac85-4d45-988b-2689cc45281f`
*   Public certificate for your ADFS server. Here is the link of how to [export](https://community.tenable.com/s/article/How-to-export-certificate-in-PEM-format-for-import-from-Windows?language=en_US) one.

Client Identifier and Relying Party ID will be shown through the following process of configuring the oauth access.

## Step 1

From the AD FS Management screen, go to **AD FS > Application Groups** and click **Add Application Group…**.

![](/attachments/q/-/q-E5kJeoyYMGL2r-_a/step_1.png)

## Step 2

1.  Fill in a name for the application group.
2.  Select **Web browser accessing a web application**.
3.  Click **Next**.

![](/attachments/a/R/aRzovoKKrhDKeVsa_a/step_2.png)

## Step 3

1.  Make note of the **Client Identifier** value.
2.  Add **Redirect URI** value, which corresponds to location of your Swarmica instance.
3.  Click **Next**.

![](/attachments/8/V/8V_dCxnuufj0f0rz_a/step_3.png)

## Step 4

1.  Select **Permit everyone**.
2.  Click **Next**.

![](/attachments/M/H/MHmg7dM9tdB1hDsw_a/step_4.png)

## Step 5

1.  Make note of the **Relying Party ID** value.
2.  Click **Next**.

![](/attachments/7/K/7K2hjPHSBfv_IXN6_a/step_5.png)

## Step 6

Click **Close**. The application is now registered in the ADFS.

![](/attachments/z/M/zMQxpWc7V1ASAQPb_a/step_6.png)

## Step 7

Right click on the created application and choose the option **Properties**.

![](/attachments/m/Z/mZ9mWwVgJhBirEKI_a/step_7.png)

## Step 8

1.  Select the **Web application** entry.
2.  Click **Edit**.

![](/attachments/T/V/TVmsX3oPHCicWwLY_a/step_8.png)

## Step 9

1.  Select **Issuance Transform Rules** tab.
2.  Click the **Add Rule** button.

![](/attachments/e/y/eySl6M18V0ePLrSI_a/step_9.png)

## Step 10

1.  Select **Send LDAP Attributes as Claims**.
2.  Click **Next**.

![](/attachments/M/E/MEriIsOwP64ub9sG_a/step_10.png)

## Step 11

1.  Give the rule a name.
2.  Select **Active Directory** as the attribute store.
3.  Configure the claims as shown below.
4.  Click **Finish**.

![](/attachments/3/N/3NV2jN5RNN6BMNki_a/step_11.png)

## Step 12

Click **Apply**.

![](/attachments/8/I/8I5isscsNkyLLC8w_a/step_12.png)

## Step 13

Restart the ADFS server. You can use console command Restart-Service `adfssrv -Force for example.`