Integrating Arc XP with Microsoft ADFS
This guide explains how to integrate Arc XP with Microsoft Active Directory Federation Services (ADFS) using SAML authentication.
If multi-factor authentication or additional security settings are needed, configure them separately from this guide.
How the integration works
This integration establishes a SAML relationship between Arc XP’s Identity Provider (Okta) and your Microsoft ADFS. When a user attempts to log in to Arc XP:
- The user is redirected to your ADFS login page.
- They log in using their ADFS credentials.
- ADFS redirects the user back to Okta.
- Okta verifies the authentication parameters and redirects the user to Arc XP.
Prerequisites
Before you begin, ensure you:
- have administrative access to your Company’s ADFS.
- understand how to configure and use ADFS.
- know how the login flow works for your users.
- identify the groups that need to be passed to Arc XP for permissions. (You can update these later.)
Step 1: Provide federation metadata
All ADFS deployments have a Federation Metadata URL. Arc XP requires either the URL or the XML content from this URL.
- Locate your Federation Metadata URL. It typically follows this format:
https://<ADFS hostname>/federationmetadata/2007-06/federationmetadata.xml - Send this URL or the XML content to Arc XP Customer Support.
- Wait for Arc XP to proceed to the next step.
Step 2: Create a relying party trust in ADFS
When Arc XP receives your metadata, they send you a file named metadata.xml. Use this file to configure ADFS as follows:
- Open ADFS Management Console.
- In the Actions pane, click Add a Relying Party Trust.
- Click Start (leave Claims Aware selected).
- On Select Data Source, choose Import Data and browse for the
metadata.xmlfile. - Click Next.
- Name the Relying Part Trust Arc Publishing, and click Next.
- On Access Control Policy, select Permit Everyone. You can customize permissions later if needed.
- Verify the configuration details, and click Next.
- Click Close.
Step 3: Configure claims
Claims populate user identity details when logging in to Arc XP.
-
If the Edit Claim Issuance Policy window does not appear, right-click the Relying Party Trust you just created and select Edit Claim Issuance Policy.
-
Click Add Rule.
-
Select Send LDAP Attributes as Claims, and click Next.
-
Name the rule Arc Publishing Okta.
-
Select Active Directory as the Attribute Store.
-
Map the following claims:
Table 1. LDAP attributeOutgoing claim typeE-Mail Addresses
emailE-Mail AddressesuserNameGiven-NamefirstnameSurnamelastnameUser-Principal-NameName ID -
Click Finish.
Step 4: Configure group mappings
Groups determine user permissions within Arc XP. You must manually configure and pass group claims.
-
Click Add Rule again.
-
Select Send Group Membership as a Claim, and click Next.
-
Configure the group details:
- Claim Rule Name - set a name for tracking.
- Group - select the group from Active Directory.
- Outgoing Claim Type - enter
groups(must be typed manually) - Outgoing Claim Value - enter the value you want to pass to Arc XP.
-
Click Finish.
-
Repeat these steps for each additional group.
Step 5: Provide group information to Arc XP
After you configure groups, send the Outgoing Claim Values to Arc XP Customer Support. Arc XP updates Okta to recognize these groups.
Step 6: Test the integration
After Arc XP confirms the setup is complete, test the login process.
-
Go to your Arc XP admin portal:
[orgId].arcpublishing.com. -
Enter your email address on the Okta login page.
The system routes the request to ADFS.
-
Log in using your ADFS credentials.
If successful, the system redirects you to Arc XP.