In order for Security Center to receive claims from an ADFS server, you need to create and configure an ADFS role within Security Center.
Before you begin
- All ADFS servers involved in the trust chain must be fully configured.
- Map the accepted remote ADFS groups to Security Center user groups.
What you should know
You need to create one ADFS role in Security Center for each root ADFS you have. In our sample scenario, your local ADFS server is your root ADFS, therefore you only need to create one ADFS role.
In a situation where you do not have a local ADFS server, but multiple independent third-party ADFS servers acting as security token services for Security Center, then you need to create an ADFS role for each of them, and add a relying party trust for Security Center to each of these ADFS server's configuration.