Configure AD FS servers for auditing - Configure claims
For each relying party that needs to be audited, the following six claim rules need to be added:
Primary SID
UPN
Client IP
Inside Corporate Network
Proxy
Forwarded Client IP
To check which claim rules have already been added:
Log in to the AD FS server with Domain Admin credentials.
Open the AD FS management console > Trust Relationships > Relying Party Trusts.
Right-click on the relying party > Edit Claim Rules (or Edit Claim Issuance Policy in case of Windows 2016), and check if all six of the above claim rules have been added.
To add any missing claim rules:
Log in to the AD FS server with Domain Admin credentials. Open the AD FS management console > Trust Relationships > Relying Party Trusts.
Right-click on the relying party > Edit Claim Rules (or Edit Claim Issuance Policy in case of Windows 2016).
Click Add Rule. From the Claim rule template drop down, select Pass Through or Filter an Incoming Rule and click Next.
In the Claim rule name field, enter a suitable name.
Under Incoming claim type, select the claim rule type which you need to add, and select Pass through all claim values.