> Full SurrealDB documentation index: https://surrealdb.com/docs/llms.txt

# ADFS

Configure Active Directory Federation Services (ADFS) as an identity provider for single sign-on in SurrealDB. Add a WS-Federation relying party trust in ADFS and an ADFS connection in SurrealDB Studio.

Connect Active Directory Federation Services (ADFS) to SurrealDB to allow members of your organisation to sign in with their Active Directory credentials. You add a relying party trust in ADFS Management, then enter your ADFS server's URL in a new connection in SurrealDB Studio.

Before you start, [verify the email domain](/docs/manage/enterprise/single-sign-on.md#step-1-verify-an-email-domain) your company uses. You also need administrator access to your ADFS server.

## Values for ADFS

The relying party trust takes two values from SurrealDB. Studio shows both in the **Set up ADFS** section of the connection form, with a copy button beside each.

| Value                          | Enter in ADFS                                   |
| ------------------------------ | ------------------------------------------------ |
| Relying party trust identifier | `urn:auth0:auth0surrealdb`                       |
| Endpoint URL                   | `https://auth.surrealdb.com/login/callback`      |

## Step 1: Add a relying party trust

1. In ADFS Management, open **Relying Party Trusts** and select **Add Relying Party Trust**.
2. Select **Claims aware**.
3. Select **Enter data about the relying party manually**.
4. Enter a display name, for example `SurrealDB`.
5. Skip the token encryption certificate.
6. Select **Enable support for the WS-Federation Passive protocol**, and enter the endpoint URL from the table above.
7. Add the relying party trust identifier from the table above.
8. Choose an access control policy, for example **Permit everyone**, and finish the wizard.

## Step 2: Add claim rules

SurrealDB needs each person's email address and name.

1. Select the new relying party trust, then **Edit Claim Issuance Policy**.
2. Select **Add Rule**, then **Send LDAP Attributes as Claims**.
3. Set **Attribute store** to **Active Directory**.
4. Map the attributes:

| LDAP attribute          | Outgoing claim type |
| ----------------------- | ------------------- |
| `E-Mail-Addresses`      | E-Mail Address      |
| `Display-Name`          | Name                |
| `User-Principal-Name`   | Name ID             |

5. Select **Finish**, then **OK**.

## Step 3: Expose the federation metadata

SurrealDB reads your server's configuration from its federation metadata endpoint, `/FederationMetadata/2007-06/FederationMetadata.xml`. Make sure this endpoint can be reached from the internet, for example by opening `https://adfs.example.com/FederationMetadata/2007-06/FederationMetadata.xml` from outside your network.

## Step 4: Add the connection in SurrealDB

1. Open **Single sign-on** in your enterprise and add a new connection.
2. Select **ADFS**.
3. Under **Name the connection**, enter a **Display name**. Members see this name on the sign-in screen.
4. Under **Enter the ADFS details**, enter the **ADFS server URL**, for example `https://adfs.example.com`.
5. Under **Route sign-in domains**, select the verified domains to send to this connection. This is optional, and you can change it later.
6. Select **Create connection**.

An ADFS connection has no client secret or certificate to enter. SurrealDB takes the signing certificate from the federation metadata.

## Next steps

If you did not route a domain when you created the connection, [route one now](/docs/manage/enterprise/single-sign-on.md#step-3-route-domains-to-the-connection). Then [choose the applications](/docs/manage/enterprise/single-sign-on.md#step-4-choose-the-applications) that people can sign in to with this connection.
