> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v2.0/configuration/setting-up-authentication/setting-up-authentication-with-adfs.md).

# Setting up authentication with ADFS

The following guide will assist you in configuring your application to use Active Directory Federation Services (ADFS) for authentication.

## Part 1: Configure a new replying party trust in ADFS

1. Open the ADFS console, expand `Trust Relationships`, right-click `Relying Part Trusts` and select `Add relying-party trust`
2. Click `Next` and select `Enter data about the relying party manually`
3. Specify `Lithnet Access Manager` as the display name
4. Select `AD FS profile`
5. Skip the encryption certificate step
6. Check the box to `Enable support for the WS-Federation Passive protocol`. Specify the base URL where your Lithnet Access Manager is hosted (e.g. `https://accessmanager.lithnet.local/`)
7. Skip the page prompting you to add additional relying-party trust identifiers
8. Optionally, configure multifactor authentication for the trust, and follow the remaining pages through to completion
9. Edit the claim rules for the application. Add a new issuance transform rule to `Send LDAP attributes as claims`
10. Set 'Issue UPN' as the claim rule name. Select `Active Directory` as the attribute store, `User-Principal-Name` as the `LDAP Attribute` and `UPN` as the outgoing claim type

## Part 2: Configure Lithnet Access Manager

![!](https://2384577883-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FGiL0iwWnyPOkaGqdhRTp%2Fuploads%2Fgit-blob-5ec8fefc00e740ba68ab16274887fe3facf6eed1%2Fui-page-authentication-wsfed-adfs.png?alt=media)

1. Open the Lithnet Access Manager Service Configuration Tool
2. Select the `App configuration\User Authentication` page
3. Select `WS-Federation` as the authentication provider type
4. In the `metadata` field, provide the metadata URL for your ADFS server (usually something like `https://adfs.lithnet.local/FederationMetadata/2007-06/FederationMetadata.xml`)
5. Enter the base URL of your application in the `Realm` field.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v2.0/configuration/setting-up-authentication/setting-up-authentication-with-adfs.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
