Configuring ADFS 3.0 as the Identity Provider  

Before you start the configuration process, make sure that the ServiceDesk Plus MSP application is running in the HTTPS mode. Then, configure ServiceDesk Plus MSP as a Relying Party Trust (RPT). This can be done either manually or using the metadata file.


To configure the Relying Party Trust manually  

  1. Open the ADFS management application.

  2. Right-click Relying Party trust and choose Add Relying Party Trust option. The Add Relying Party Trust Wizard opens.
    ADFS_1

  3. Choose Claims Aware and click Next.

    ADFS_2
  4. Choose Enter data about the relying party manually and click Next.

    ADFS_3
  5. Provide a Display Name and add Notes if any.
  6. Click Next.

    ADFS_4
  7. The next window is to upload the encryption certificate. You can skip this step as ServiceDesk Plus MSP does not support encryption of the SAML responses.
  8. Click Next.

    ADFS_5
  9. Select Enable support for SAML 2.0 Web SSO portal checkbox.
  10. Enter the Assertion Consumer URL of ServiceDesk Plus MSP in the Relying Party SAML 2.0 SSO Service URL field.
  11. Click Next.

    ADFS_6
  12. In Relying Party Trust identifier, enter the Entity ID of ServiceDesk Plus MSP and click Add.
  13. Click Next.

    ADFS_7
  14. Choose Access Control Policy from the list.

    ADFS_8
  15. Click Next.

    ADFS_9
  16. Click Close. The Edit Claim Insurance Policy for SDP window opens.

    ADFS_10
  17. Minimize the window and double-click Relying Party Trust to open its properties.
  18. In the Signature tab, add the certificate file downloaded from ServiceDesk Plus MSP by clicking the Add button.

    ADFS_11
  19. In the Endpoints tab, click Add SAML and choose the Endpoint Type as SAML Logout.
  20. Enter the Single Logout Service URL of ServiceDesk Plus MSP in the Trusted URL and Response URL fields.
  21. Click OK.

    ADFS_12


    ADFS_13
  22. Under the Advanced tab, choose the Algorithm used in ServiceDesk Plus MSP from the drop-down.
  23. Click Apply.

    ADFS_14

Configuring Relying Party Trust using the metadata file  

  1. Open the ADFS management application.

  2. Right-click Relying Party trust and choose Add Relying Party Trust option. The Add Relying Party Trust Wizard opens.

    ADFS_15

  3. Choose Claims Aware and click Next.

    ADFS_16

  4. Choose Import data about the relying party from a file.

  5. Click Browse and upload the SP metadata file.

  6. Click Next.

    ADFS_17
  7. Provide a Display Name for the RPT and click Next.

    ADFS_18
  8. Choose Access Control Policy and click Next.

    ADFS_19
  9. Click Next.

    ADFS_20
  10. Click Close to complete the configuration.
    ADFS_21 
  11. After configuring ServiceDesk Plus MSP as a Relying Port Trust, the Edit Claim Insurance Policy for SDP window opens.
  12. Click Add Rule.

    ADFS_22
  13. In the Claim Rule template drop-down, choose Transform an Incoming Claim option and click Next.

    ADFS_23
  14. Provide a Claim Rule Name.
  15. Choose Windows Account Name as the Incoming claim type, Name ID for Outgoing claim type, and Transient Identifier for Outgoing Name ID format. Currently, ServiceDesk Plus MSP supports Transient, Persistent, and Email Address as Name ID formats.
    • To login using your username and domain, select Transient or Persistent.
    • To login using your email address, select EmailAddress.
  16. Click Finish.

    ADFS_24

To download the IdP Certificate   

  1. Go to Services >> Certificates and click the Token-signing certificate.

    ADFS_25

  2. Under the Details tab, click Copy to File option. The Certificate Export Wizard opens.

    ADFS_26
  3. Choose DER encoded binary X.509 (.CER) and click Next

    ADFS-27
  4. Enter the location to save the file and provide the file name at the end of the URL.
  5. Click Next. You must upload this certificate in ServiceDesk Plus MSP application to complete the integration

    Note:

    The login and logout URLs for ADFS 3.0 are as follows:

    Login URL: https://yourdomainname/adfs/ls
    Logout URL: https://yourdomainname/adfs/ls?SingleSignOut=SingleSignOut
     

    ADFS_28

  6. Click Finish
    ADFS_29

You have now configured ServiceDesk Plus MSP as a service provider in ADFS 3.0. Go to the SAML configuration page in ServiceDesk Plus MSP and provide the IdP details to complete the integration.

© 2025 Zoho Corporation Pvt. Ltd. All rights reserved.