SharePoint - Migrate users from Windows claims to ADFS

by Robi 20. September 2016 21:09

In last few projects we needed to migrate windows claims users to SAML claims.

I wrote a script to automate this process.

The script checks Trusted Token Issuers, checks which claim is identifier claim with selected token issuer and then sets the user prefix accordingly.

For example, if email is set as identifier claim, then user prefix is "i:05.t" and if UPN is selected than the prefix is "i:0e.t".

Based on claim mapping set on ADFS server for role claims, I also set group prefix and group login accordingly. For example, if on ADFS server role claims are set as "Token-Groups - Qualified by Long Domain Name", than the group login name is set as [long domain name]\[group samAccountName] e.g. "kompas-xnet.si\sg_SharePointUsers".

For role claim, you can use:

  1. Token-Groups-Qualified-by-Long-Domain-Name
  2. Token-Groups-Qualified-by-Domain-Name
  3. Token-Groups-Unqualified-Names

   

The script also logs user migration. It checks default diagnostic logging location and creates log files in that folder.

The script must be run on SharePoint server and requires that ActiveDirectory PowerShell module is installed.

   

Instructions

In order to use the script, download the file to "c:\Scripts" on the server, run PowerShell as Administrator and type the following:

. "C:\Scripts\Migrate-UsersFromAdToADFS.ps1" -roleClaim Token-Groups-Qualified-by-Long-Domain-Name -url https://test.kompas-xnet.si -farmAdmin "sp13_farm_admin"

 

You must set "roleClaim" parameter. It is a set of predefined values, so you do not need to type the values, you can just tab them. You must set the valid "URL" address of the local SharePoint site, on which you would like to migrate your users.

You also need to specify "farmAdmin" account, your administrative account, which will be skipped during migration.

You can also add the Verbose switch if needed.

 

Script Output

 

 

Hopefully, the script covers some scenarios for migrating users from windows claims to SAML claims.

 If you have any comments or suggestions, please contact me at: robi@kompas-xnet.si

 

Download

Tags:

Add comment

Calendar

<<  May 2017  >>
MonTueWedThuFriSatSun
24252627282930
1234567
891011121314
15161718192021
22232425262728
2930311234

View posts in large calendar

Page List

Month List