> ## Documentation Index
> Fetch the complete documentation index at: https://launchdarkly.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Active Directory Federation Services (ADFS)

<View title="Developer" />

<View title="Federal docs" />

<View title="EU docs" />

This topic explains how to configure SSO integration between a self-hosted Active Directory Federation Services (ADFS) server and LaunchDarkly.

ADFS is a service provided by Microsoft as a standard role for Windows Server. It provides a web login using existing Active Directory credentials.

<Note>
  **Troubleshooting ADFS-based SSO**

  If you need information about ADFS errors during configuration, troubleshoot it by accessing the ADFS logs in the Windows Event Viewer.
</Note>

## Prerequisites

To give your organization access to LaunchDarkly through ADFS, you need the following components:

* An Enterprise LaunchDarkly account.
* A signed SSL certificate.
* An Active Directory instance where all users have an email address attribute.
* A Microsoft Server instance with ADFS installed and configured.

<Danger>
  **Setting up ADFS**

  This topic does not tell you how to set up ADFS. To learn how to set up ADFS, read [Microsoft's documentation](https://learn.microsoft.com/en-us/previous-versions/dynamicscrm-2016/deployment-administrators-guide/hh699811\(v=crm.8\)).
</Danger>

## Set up LaunchDarkly fields

Here is a table explaining LaunchDarkly fields:

<table>
  <thead>
    <tr>
      <th>LaunchDarkly field</th>
      <th>Notes</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td>Sign-on URL</td>

      <td>
        Default value: <code>[https://YOUR-DOMAIN/adfs/ls/](https://YOUR-DOMAIN/adfs/ls/)</code>. <br />
        If the default value fails, confirm that the endpoint is enabled and the URL path is correct.

        <br />

        Find the endpoint in Service, then Endpoints. Search for an endpoint with the
        <code>SAML 2.0/WS-Federation</code> type.
      </td>
    </tr>

    <tr>
      <td>X.509 Certificate</td>

      <td>
        Copy the Token Signing certificate to a Base-64 encoded X.509 file and import it into LaunchDarkly
      </td>
    </tr>
  </tbody>
</table>

For more information on configuring LaunchDarkly's SSO, read [Single sign-on](/docs/home/account/sso).

## Add Relying Party Trust

To add the Relying Party Trust:

1. Log into the ADFS Management tool.
2. Click **Add Relying Party Trust...**. The Add Relying Party Trust Wizard appears:

<Frame caption="The ADFS Management tool, with the &#x22;Add Relying Party Trust...&#x22; option called out.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-add-party-trust.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=0fd79f3313d729097cb3b41d04e10502" alt="The ADFS Management tool, with the &#x22;Add Relying Party Trust...&#x22; option called out." width="1189" height="365" data-path="images/__third_party/adfs-add-party-trust.png" />
</Frame>

3. Click **Start**. Keep the default value, which is **Claims aware**:

<Frame caption="The &#x22;Welcome&#x22; screen for the setup wizard.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-wizard-claims-aware.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=edff7449c1436d2e13231abaea945237" alt="The &#x22;Welcome&#x22; screen for the setup wizard." width="715" height="580" data-path="images/__third_party/adfs-wizard-claims-aware.png" />
</Frame>

4. Choose **Enter data about the relying party manually**:

<Frame caption="The Select Data Source screen.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-wizard-enter-data-manually.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=867131f78ed3f29e54165d7b57867313" alt="The Select Data Source screen." width="718" height="587" data-path="images/__third_party/adfs-wizard-enter-data-manually.png" />
</Frame>

5. Click **Next**. The "Specify Display Name" screen appears.
6. Set a display name of your choosing.
7. Click **Next**. The "Configure Certificate" screen appears.
8. You do not need to choose a certificate. Click **Next**.
9. Select **Enable support for the SAML 2.0 WebSSO protocol**.
10. Enter the **Assertion consumer service URL** from the SSO section of LaunchDarkly into the **Relying party SAML 2.0 SSO service URL** field.
11. Click **Next**.
12. In the **Relying party trust identifier** field, enter `app.launchdarkly.com`.
13. Click **Add**.
14. Click **Next**. The "Choose Access control Policy" screen appears.
15. You do not need to change any access control policies. Click **Next**.
16. Review your changes and click **Next**.
17. If you are satisfied with the configuration, click **Close**.

After you have successfully completed this procedure, a new LaunchDarkly trust will appear in the ADFS Management tool.

## Set up claim issuance policies

To set up a claim issuance policy:

1. Log into the ADFS Management tool.
2. Select the **LaunchDarkly Trust**.
3. Click **Edit Claim Issuance Policy...** in the menu. The "Edit Claim Issuance Policy" window appears.
4. Click **Add Rule**.
5. Set **Claim rule template** to "Transform an Incoming Claim."
6. Click **Next**:

<Frame caption="The &#x22;Select Rule Template&#x22; screen.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-select-rule-template.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=5036fd87a7b811589db33ceb5756376a" alt="The &#x22;Select Rule Template&#x22; screen." width="715" height="579" data-path="images/__third_party/adfs-select-rule-template.png" />
</Frame>

7. Set the following options:

* Claim rule name: Enter a human-readable name, such as "Email to NameID."
* Incoming claim type: **E-Mail Address**
* Outgoing claim type: **Name ID**
* Outgoing name ID format: **Email**

8. Select **Pass through all claim values**.
9. Click **Finish**.

ADFS is now configured with LaunchDarkly.

For more information on claim rules, read Microsoft's [Create a Rule to Transform an Incoming Claim](https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-transform-an-incoming-claim).

### Configure custom roles

You can map LaunchDarkly custom role attributes to ADFS using a claim issuance policy. To learn more about SSO provisioning for roles, read [Roles](/docs/home/account/roles).

Before you can map custom role attributes, you must get your ADFS groups. To learn how, read Microsoft's [Create a Rule to Send Claims Using a Custom Rule](https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-rule-to-send-claims-using-a-custom-rule).

Your rule will look something like this:

<Frame caption="The &#x22;Edit Rule&#x22; window.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-get-groups.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=bd6f718976c4fb17c2f15476447d06d5" alt="The &#x22;Edit Rule&#x22; window." width="1367" height="1463" data-path="images/__third_party/adfs-get-groups.png" />
</Frame>

To send claims using a custom rule:

1. Log into the ADFS Management tool.
2. Select **LaunchDarkly Trust**.
3. Click **Edit Claim Issuance Policy...** in the menu. The "Edit Claim Issuance Policy" window appears.
4. Click **Add Rule**.
5. Set **Claim rule template** to **Send Claims using a custom rule**.
6. Click **Next**.
7. Enter a human-readable name, such as "Map groups to LaunchDarkly custom roles."
8. In the Custom rule window, enter the following:

   <CodeGroup>
     ```text title="ADFS" lines wrap theme={null}
     c:[Type == "http://temp/variable"]
      => issue(Type = "customRole", Value = c.Value)
     ```
   </CodeGroup>

Here is an image of the custom rule:

<Frame caption="A custom rule entered in the &#x22;Edit Rule&#x22; window.">
  <img src="https://mintcdn.com/launchdarkly/unfRSXbmQkdGxJjN/images/__third_party/adfs-map-groups-to-roles.png?fit=max&auto=format&n=unfRSXbmQkdGxJjN&q=85&s=fbb5c49d044573f03509741bd038853b" alt="A custom rule entered in the &#x22;Edit Rule&#x22; window." width="1363" height="1467" data-path="images/__third_party/adfs-map-groups-to-roles.png" />
</Frame>

9. Click **OK**.

You can now assign ADFS members to custom role groups using the "Member of" tab within user properties.

<Note>
  **Removing existing roles**

  SAML ignores empty fields if used in **Roles** or **customRoles**. To clear all existing roles, enter an empty string "" into the field.
</Note>

## Test drive and enable

After you successfully complete the procedures in this topic, you can log in through ADFS when test-drive mode is enabled. To learn more, read [Test-drive mode](/docs/home/account/saml#test-drive-mode).

If you are able to successfully log in with test-drive mode enabled, you can enable SSO for the rest of your organization. To learn more, read [Single sign-on](/docs/home/account/sso).
