locked
ADFS 2016 no device contextual claims produced RRS feed

Answers

  • I checked the logs after a scheduled reboot and the desired claims are now being generated. I have a call in to support to find out where the miscommunication is/was regarding this functionality.

    Issued identity: 

    http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser  true  http://schemas.microsoft.com/2014/03/psso  true  http://schemas.microsoft.com/2014/09/devicecontext/claims/trusttype  Workplace  http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown  true  http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged  false  http://schemas.microsoft.com/2012/01/devicecontext/claims/osversion  10.0 (10586)  http://schemas.microsoft.com/2012/01/devicecontext/claims/ostype  Windows 10 Enterprise

    Monday, February 27, 2017 11:25 PM

All replies

  • Well this took a left turn... I opened a Premier support case and this functionality isn't available to Windows 10 with automatic device registration (described here). Azure AD Conditional Access must be used instead of ADFS claim rules that allow/deny based on the device state. I'm going to miss the flexibility of claim rules.
    Friday, February 24, 2017 2:38 AM
  • I checked the logs after a scheduled reboot and the desired claims are now being generated. I have a call in to support to find out where the miscommunication is/was regarding this functionality.

    Issued identity: 

    http://schemas.microsoft.com/2012/01/devicecontext/claims/isregistereduser  true  http://schemas.microsoft.com/2014/03/psso  true  http://schemas.microsoft.com/2014/09/devicecontext/claims/trusttype  Workplace  http://schemas.microsoft.com/2014/02/devicecontext/claims/isknown  true  http://schemas.microsoft.com/2012/01/devicecontext/claims/ismanaged  false  http://schemas.microsoft.com/2012/01/devicecontext/claims/osversion  10.0 (10586)  http://schemas.microsoft.com/2012/01/devicecontext/claims/ostype  Windows 10 Enterprise

    Monday, February 27, 2017 11:25 PM