Setting the claim‑issuance policy for GroupRule
-
From the AD FS window, click Relying Party Trusts, and then right-click the applicable relying‑party trust.
-
Click Edit Claim Issuance Policy, and then Add Rule.
-
From the Claim rule template list, select Send LDAP Attributes as Claims.
-
In the Claim rule name field, type GroupRule.
-
From the Attribute store list, select Active Directory.
-
Set LDAP attribute to Token-Groups - Unqualified Names, and then set Outgoing Claim Type to MVEGroup.
-
Click Finish.