ADFS - Restrict to AD Group

This can be done by adding a so-called Issuance Authorization Rule.

Step-by-step:

  • Open AD FS Management Center
  • Expand Trust Relationsships
  • Select Relying Party Trusts
  • Right click the required trust
  • Click Edit Claim Rules
  • Goto the Issuance Authorization Rules tab
  • Delete the default Permit Access To All Users rule
  • Click Add Rule
  • Select Permit or Deny Users Based on an Incoming Claim
  • Incoming Claim Type, select Group SID
  • Click Browse at Incoming claim value
  • Select the required group
  • You're done