Step 2: Configuring Identity Provider for single sign-on

As the second step, configure BigFix Inventory server as a relying party to consume claims from the Identity Provider. Perform the configuration based on the spMetadata.xml file that you downloaded from BigFix Inventory.

About this task

BigFix Inventory supports single sign-on (SSO) through Active Directory Federation Services (AD FS). If you are using Azure, you must configure Azure to AD FS to authenticate through the SSO and access the application. The following procedure is based on the example of AD FS.


  1. Log in to the computer where Active Directory Federation Services are installed.
  2. Copy the spMetadata.xml file from your computer to a directory on the AD FS server.
  3. Click the Start rectangle in the lower-left area of the screen in Windows 2012 and then click the AD FS Management tile.
  4. In the left navigation tree of the AD FS application, expand AD FS > Trust Relationships > Relying Party Trusts.
  5. In the Relying Party Trusts pane on the right, click Add Relying Party Trust. A wizard opens. Click Start.
  6. Select Import data about the relying party from a file.
  7. Click Browse, select the spMetadata.xml file and click Open. Click Next.
  8. On the new pane, provide the Display name for your ADFS service. Click Next.
  9. Leave the option Permit all users to access the relying party selected, and click Next.
  10. On the Ready to Add Trust pane, click Next.
  11. On the Finish pane, click Close. The Edit Claim rules window opens.
  12. Click the Add Rule button in the lower left corner. The Add Transform Claim Rule wizard opens. Click Next.
  13. In the Claim Rule template, type Name ID rule.
  14. From the Attribute store drop-down list, select Active Directory.
  15. In the Mapping of LDAP Attributes to outgoing claim types section, click the first drop-down list and select User Principal Name. From the second list, select Name ID.
  16. Repeat the step to achieve the following configuration and click Finish.
    Table 1. Mapping of LDAP Attributes to outgoing claim types
    LDAP Attribute Outgoing Claim Type
    User-Principal-Name Name ID
    E-Mail-Addresses E-Mail Address
    Token-Groups - Qualified by Long Domain Name Group
    SAM-Account-Name Windows account name
  17. In the Edit Claim rules window, click Apply and OK.

What to do next

Enable single sign-on in BigFix Inventory.