> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-bp-2641-crowdstrike-integration.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML: ADFS Configuration

> This document provides instructions for creating an application within ADFS for compatibility with BloodHound Enterprise.

export const IDPIntro = ({auth_mode}) => {
  const mode = (auth_mode || '').toUpperCase();
  const isOIDC = mode === 'OIDC';
  const href = isOIDC ? '/manage-bloodhound/auth/oidc' : '/manage-bloodhound/auth/saml';
  const label = isOIDC ? 'OIDC' : 'SAML';
  return <Tip>
      See <a href={href}>{label} in BloodHound</a> for order of operations, general {label} setup, and user configuration in BloodHound.
    </Tip>;
};

<img noZoom src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=2b8e51d7e5a52c262dd70a93b9024f7e" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

<IDPIntro auth_mode="SAML" />

## Create an Application

1. In the AD FS management console, right-click on Relaying Party Trust and click “Add Relaying Party Trust”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-25.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=8e4923acb2a55d1886d3921c936e26fe" width="936" height="478" data-path="assets/image-2-25.png" />
</Frame>

2. Choose “Claims aware” and click “Start”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-26.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=ff31977db35c2dc7cfc0853e32c0694a" width="936" height="762" data-path="assets/image-2-26.png" />
</Frame>

3. Insert the metadata URL based on your chosen name and click “Next.”

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-27.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=1aeee0f51933a8ccf46446e8aec7fcb9" width="936" height="762" data-path="assets/image-2-27.png" />
</Frame>

4. Enter the preferred display name and click “Next.”

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-28.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=dce0642d9841b92956c5e7ed01977115" width="936" height="762" data-path="assets/image-2-28.png" />
</Frame>

5. Choose the desired Access Control Policy. (Note that access and permissions are configured within BloodHound Enterprise).

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-29.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=1fbc23b0607297e015ad161737c96787" width="936" height="762" data-path="assets/image-2-29.png" />
</Frame>

6. Review the information presented and click “Next”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-30.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=9bf1c0e18204635896925fac42996625" width="936" height="762" data-path="assets/image-2-30.png" />
</Frame>

7. Leave the “Configure claims issuance policy for this application” box checked and click “Close”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-31.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=bd479f8e3b432b1740f2e532b2beb05d" width="936" height="762" data-path="assets/image-2-31.png" />
</Frame>

## Complete SAML Integration Configuration

1. On the “Edit Claim Issuance Policy” dialog box, click “Add Rule…”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-32.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=41441601ba6450318f06fa4fced99c27" width="936" height="1046" data-path="assets/image-2-32.png" />
</Frame>

2. Choose “Send LDAP Attributes as Claims” and click “Next.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-33.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=df0e5fee67e4dee863de17c4c505ea54" width="936" height="762" data-path="assets/image-2-33.png" />
</Frame>

3. Fill out the following and click “Finish”.

   LDAP Attribute: E-Mail-Addresses
   Outgoing Claim Type : E-Mail Address

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-34.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=d92ce526fdf6b0e0727f0e5110528308" width="936" height="762" data-path="assets/image-2-34.png" />
</Frame>

4. Click “Add Rule” to add another claim rule.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-35.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=7875daf7eee8eca3b4e095b1fc97e27c" width="936" height="1046" data-path="assets/image-2-35.png" />
</Frame>

5. Choose “Transform and Incoming Claim” and click “Next”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-36.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=c52fae438fcd5890193bfa321e44f6bd" width="936" height="762" data-path="assets/image-2-36.png" />
</Frame>

6. Fill out the following and click “Finish”.

   Incoming claim type: E-Mail Address
   Outgoing claim type: Name ID
   Outgoing name ID format: Email
   Choose “Pass through all claim values”

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-37.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=57bb0d41e8941ae8ef835374020adb68" width="936" height="762" data-path="assets/image-2-37.png" />
</Frame>

7. Click “Apply”.

<Frame>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/oIy7WEPaKrQdJo1n/assets/image-2-38.png?fit=max&auto=format&n=oIy7WEPaKrQdJo1n&q=85&s=f992f8c801a1a57b58859d0328f15921" width="936" height="1046" data-path="assets/image-2-38.png" />
</Frame>

8. Download the metadata file provided by your ADFS environment. By default, this is hosted at: [https://YOURDOMAIN/federationmetadata/2007-06/federationmetadata.xml](https://YOURDOMAIN/federationmetadata/2007-06/federationmetadata.xml)
9. Follow the instructions at [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml) to create the SAML provider in BloodHound Enterprise.
