<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Aptos",sans-serif;
        mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#467886;
        text-decoration:underline;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Aptos",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;
        mso-ligatures:none;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Forgot to attach attribute filter<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><AttributeFilterPolicy id="FilterPolicyObject-Proxy-FromAzure-byIssuer-Type"><o:p></o:p></p>
<p class="MsoNormal">    <PolicyRequirementRule xsi:type="Issuer" value= *** /><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureDisplayname" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureGivenname" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureSurname" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureAuthnmethodsreferences" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureIdentityprovider" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureTenantid" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureEmailaddress" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureObjectidentifier" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal">    <AttributeRule attributeID="azureName" permitAny="true" /><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"></AttributeFilterPolicy><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-family:"Calibri",sans-serif;mso-ligatures:none">From:</span></b><span style="font-family:"Calibri",sans-serif;mso-ligatures:none"> Ramaiah, Vanna G.
<br>
<b>Sent:</b> Thursday, February 13, 2025 5:39 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> saml proxying shib to ADFS - No transcoding rule for Attribute <o:p>
</o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am following this article to set up proxt to adfs. <o:p></o:p></p>
<p class="MsoNormal"><a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1467056889/Using+SAML+Proxying+in+the+V4+Shibboleth+IdP+to+connect+with+Azure+AD</a>
<o:p></o:p></p>
<p class="MsoNormal">From debug logs, I can confirm that adfs is passing the attributes to shib.
<span style="color:#0A2F41">Attribute filter.xml and attribute-resolver.xml are setup.  azureClaims.xml is included in conf/attributes/default-rules.xml.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I see the below logs.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">DEBUG [org.opensaml.saml.saml2.assertion.SAML20AssertionValidator:876] - Assertion contains at least 1 SubjectConfirmation, proceeding with subject confirmation<o:p></o:p></p>
<p class="MsoNormal">INFO [net.shibboleth.idp.saml.saml2.profile.impl.ValidateSAMLAuthentication:511] - Profile Action ValidateSAMLAuthentication: No transcoding rule for Attribute (Name 'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name', NameFormat:
 'urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified')<o:p></o:p></p>
<p class="MsoNormal">DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.ValidateSAMLAuthentication:482] - Profile Action ValidateSAMLAuthentication: Incoming SAML Attributes mapped to attribute IDs: []<o:p></o:p></p>
<p class="MsoNormal">Profile Action ValidateSAMLAuthentication: SAML authentication succeeded for 'null'<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Here is sample of azureClaims. I turned off scope.<o:p></o:p></p>
<p class="MsoNormal"><property name="properties"><o:p></o:p></p>
<p class="MsoNormal">                <props merge="true"><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="id">azureName</prop><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="transcoder">SAML2StringTranscoder</prop><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="saml2.name"><a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name%3c/prop">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name</prop</a>><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="saml2.nameFormat">urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified</prop><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="displayName.en">Name</prop><o:p></o:p></p>
<p class="MsoNormal">                    <prop key="description.en">Azure UPN of an account expected to be scoped thus transcoded that way</prop><o:p></o:p></p>
<p class="MsoNormal">                </props><o:p></o:p></p>
<p class="MsoNormal">            </property><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="color:#0A2F41">What am I missing?</span><o:p></o:p></p>
</div>
</body>
</html>