Enabling single sign-on via ADFS

Requirements

  • Admin in Exchange
  • ADFS 2.0+
  • Advanced Authentication + User Management

This article covers:


Robin supports ADFS (Active Directory) single sign-on with SAML 2.0, which is available on ADFS version 2.0 and above. For general questions about SAML support, see Enabling single sign-on via SAML 2.0. SAML authentication is available for organizations on Enterprise plans.

This guide uses the most likely ADFS defaults. If some fields below differ from your default ADFS claims, use transform rules in ADFS to send the right format back to Robin. You do not need to change anything on the service provider side.

Add your ADFS identity provider to Robin

  1. As an administrator, go to Manage > Integrations. Scroll down to Authentication methods to find the SAML SSO option.
  2. Select Add. 2023-10-11_15-01-50.png
  3. The configuration options open.

Set up ADFS as a "Custom" type. For a default ADFS install, set these configuration options in Robin:

  • SAML SSO URL: https://yourdomain.com/adfs/ls
  • Identity Provider Issuer: https://yourdomain.com/adfs/services/trust

To confirm your server's Federation Service Properties, right-click the "Services" folder in ADFS, then select "Edit Federation Service Properties". If you do not see this option, check that you use ADFS version 2.0 or higher. ADFS 1.0 does not support SAML 2.0.

2023-10-11_15-27-43.png

Check your Issuer URL

Confirm your ADFS server's Issuer URL. Some servers send http://yourdomain.com and not https://yourdomain.com. If the URL differs from the one you set in Robin, Robin cannot match incoming requests to your account. To fix this, change the URL in Robin to match the issuer your identity provider sends.

You get the certificate from ADFS later in this guide. For now, expand Advanced Options and change 2 fields:

  • Uncheck Encrypt Assertion
  • Check "Windows" under Auth Context. You can also leave "Password Protected Transport" enabled.

The result looks similar to this:

ADFS SAML Configuration

Complete the rest of the setup with Powershell or by hand in your ADFS management console.

Option 1: Powershell

Download this file first: RelyingPartyTrustClaimRules.xml

Add-ADFSRelyingPartyTrust -Name "Robin Powered" -Identifier "https://robinpowered.com"
Import-Clixml "FULL PATH TO DOWNLOADED TRUST CLAIMS XML" | foreach-object {$samlEndpoints = foreach ($endpoint in $_.SamlEndpoints){New-ADFSSamlEndpoint -Protocol $endpoint.Protocol -Uri $endpoint.Location -Binding $endpoint.Binding -IsDefault $endpoint.IsDefault -Index $endpoint.Index -ResponseUri $endpoint.ResponseLocation}; Set-ADFSRelyingPartyTrust -TargetName "Robin Powered" -IssuanceTransformRules $_.IssuanceTransformRules -SamlEndpoint $samlEndpoints -SignatureAlgorithm $_.SignatureAlgorithm} 

Option 2: Manual Configuration

In the AD FS management console, first add a Relying Party Trust for Robin. Then update the claims to include the user attributes that SAML authentication needs.

Add Robin as a Relying Party Trust

In the Actions panel of the AD FS management console, select Add Relying Party Trust to open the setup wizard.

Add a trust party wizard

Select Enter data about the relying party manually.

Add a display name you recognize, such as "Robin" or "Robin Powered", then select Next.

Display name for relying trust party

Select AD FS Profile, then skip the next step. This setup does not need token encryption.

Select Enable support for the SAML 2.0 WebSSO protocol and enter https://dashboard.robinpowered.com/sso/saml/custom as the relying party URL.

Add your SSO URL for Robin

Enter https://robinpowered.com as the Entity ID.

Robin Entity ID

Select Permit all users to access this relying party.

Confirm the settings are correct, then save and close the wizard. The trust for Robin now exists in AD. Update the claims before you connect with SAML.

Add claims

Right-click the trust you created in the last section, and select Properties.

Under the Advanced tab, confirm the signature algorithm is SHA-256. Close the window.

SHA 265 for SAML

Right-click the trust for Robin again, and select Edit Claims.

In the new window, open the Issuance Transform Rules tab and select Add Rule > Send LDAP Attributes as Claims

Enter a Claim rule name you recognize (for example, "Robin SAML Attributes") and set Attribute store to Active Directory. Map the LDAP attributes to the Outgoing Claim Types below. Your attributes can differ. For example, your email addresses might be stored in a different attribute.

The outgoing claim types for Robin are case-sensitive:

  • Given-Name (LDAP) > "FirstName" (Outgoing Claim Type)
  • Surname > "LastName"
  • E-Mail-Addresses > "Email" (or whichever field you use for email)

AD FS Claim to SAML Attribute mapping

To confirm the claims are correct, select "View Rule Language". You see something like this:

c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"] => issue(store = "Active Directory", types = ("FirstName", "LastName", "Email"), query = ";givenName,sn,mail;{0}", param = c.Value);

Select "OK" to close the window, then select Add Rule > Transform an Incoming Claim.

Give this rule a name such as "Robin Name ID Transform", then set these fields:

  • Incoming claim type: E-Mail Address
  • Outgoing claim type: Name ID
  • Outgoing Name ID format: Email
  • Enable Pass through all claim values

Map Name ID to email

Troubleshooting InvalidNameIDPolicy

If you followed these steps and still cannot sign in, check the Event Viewer logs in ADFS for more information. A message such as "Actual NameID properties: null" in the response means ADFS did not find the email address with the attribute mapping above.

The NameID is a required field. InvalidNameIDPolicy errors usually mean ADFS cannot find a matching field for "Email". Depending on your configuration, you may need to change the "Incoming claim type" to Windows account name.

image_png__469_163_.jpg

View Rule Language now looks like this:

c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"]=> issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");

Select "OK" to close the window, then select Add Rule > Send Claims Using a Custom Rule.

Enter a Claim rule name you recognize (for example, "Robin Email Transform"). Paste this text as a custom rule:

c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"] => issue(store = "Active Directory", types = ("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"), query = ";mail;{0}", param = c.Value);

If this transform rule causes an InvalidNameIDPolicy error, use this transform:

c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] == "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"] => issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = c.Value, ValueType = c.ValueType);

Copy the certificate

In the AD FS management console, go to Service > Certificates, right-click and select View Certificate.

View certificate in ADFS

Under the Details tab, select Copy to File to begin the export wizard.

Select Base-64 encoded X.509 (.CER), then choose where to save your certificate. Keep the defaults in the rest of the wizard: select Next or OK until it finishes.

Copy the contents of the certificate file you created, and paste it into the SAML configuration in Robin. Save your configuration. SAML is enabled for your account.

References

Troubleshooting

If you completed the steps above and still get errors, check the ADFS logs in Event Viewer. Your configuration can differ, and Event Viewer is the fastest way to see details about the error shown to Robin. For the full steps, see Check ADFS logs for SAML sign-in errors.

exchange-2013_robinpowered_com.png

Articles in this section

Was this article helpful?
6 out of 13 found this helpful
Share