Hi All -
I give up trying to figure what went wrong with this. I have ClaimsPrincipal defined AuthorizationPolicy, checked in UD console it returned true as well as checking ADgroup belongs under my name. Any idea?
21:34:34 [Debug] AuthorizationService TryRunClaimsAuthorization
21:34:34 [Debug] AuthorizationService Session ID: b40d1768-796e-4b33-99eb-fe7562f100a2
21:34:34 [Debug] AuthorizationService No valid authorization policies for session.
21:34:34 [Debug] AuthorizationService No valid roles for session.
21:34:34 [Debug] AuthorizationService Setting access and ID token.
21:34:34 [Debug] AuthorizationService Checking page home.
21:34:34 [Debug] AuthorizationService No authorization policies or roles defined.
21:34:34 [Debug] AuthorizationService Page authorized.
21:34:34 [Debug] AuthorizationService Checking page add new user.
21:34:34 [Debug] AuthorizationService No authorization policies or roles defined.
21:34:34 [Debug] AuthorizationService Page authorized.
21:34:34 [Debug] AuthorizationService Checking page sanity check.
21:34:34 [Debug] AuthorizationService Authorization policy result: False
21:34:34 [Debug] AuthorizationService No authorization policies or roles defined.
$AdminPolicy = New-UDAuthorizationPolicy -Name ‘Admin’ -Endpoint {
param($ClaimsPrincipal)
$ClaimsPrincipal.HasCLaim("http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid", "S-1-5-21-2763872571-2999947588-3099097816-21XX125")
}
PS UD:\> $ClaimsPrincipal.HasCLaim("http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid", "S-1-5-21-2763872571-2999947588-3099097816-21XX125")
Executing...
True