Connect Active Directory Federation Services (ADFS) to SurrealDB to allow members of your organisation to sign in with their Active Directory credentials. You add a relying party trust in ADFS Management, then enter your ADFS server's URL in a new connection in SurrealDB Studio.
Before you start, verify the email domain your company uses. You also need administrator access to your ADFS server.
Values for ADFS
The relying party trust takes two values from SurrealDB. Studio shows both in the Set up ADFS section of the connection form, with a copy button beside each.
| Value | Enter in ADFS |
|---|---|
| Relying party trust identifier | urn:auth0:auth0surrealdb |
| Endpoint URL | https://auth.surrealdb.com/login/callback |
Step 1: Add a relying party trust
In ADFS Management, open Relying Party Trusts and select Add Relying Party Trust.
Select Claims aware.
Select Enter data about the relying party manually.
Enter a display name, for example
SurrealDB.Skip the token encryption certificate.
Select Enable support for the WS-Federation Passive protocol, and enter the endpoint URL from the table above.
Add the relying party trust identifier from the table above.
Choose an access control policy, for example Permit everyone, and finish the wizard.
Step 2: Add claim rules
SurrealDB needs each person's email address and name.
Select the new relying party trust, then Edit Claim Issuance Policy.
Select Add Rule, then Send LDAP Attributes as Claims.
Set Attribute store to Active Directory.
Map the attributes:
| LDAP attribute | Outgoing claim type |
|---|---|
E-Mail-Addresses | E-Mail Address |
Display-Name | Name |
User-Principal-Name | Name ID |
Select Finish, then OK.
Step 3: Expose the federation metadata
SurrealDB reads your server's configuration from its federation metadata endpoint, /FederationMetadata/2007-06/FederationMetadata.xml. Make sure this endpoint can be reached from the internet, for example by opening https://adfs.example.com/FederationMetadata/2007-06/FederationMetadata.xml from outside your network.
Step 4: Add the connection in SurrealDB
Open Single sign-on in your enterprise and add a new connection.
Select ADFS.
Under Name the connection, enter a Display name. Members see this name on the sign-in screen.
Under Enter the ADFS details, enter the ADFS server URL, for example
https://adfs.example.com.Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.
Select Create connection.
An ADFS connection has no client secret or certificate to enter. SurrealDB takes the signing certificate from the federation metadata.
Next steps
If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.