Zero Trus Secure Access (ZSTSA) Internet Access identifies users based on the User
Principal Name (UPN), not the email address. If your IdP sends an email address instead
of a UPN in the SAML response, the rule match fails. Configure your IdP to send the
UPN in the NameID field. Once the configuration is complete, ask the end user to log out and re-authenticate.Microsoft Entra ID (formerly Azure AD)
Procedure
- Log in to the Microsoft Entra admin center.
- Navigate to Enterprise applications and select your application for Trend Vision One.
- In the left menu, select Single sign-on.
- In the Attributes & Claims section, click Edit.
- Locate the Unique User Identifier (Name ID) claim.
- Click on it to edit and change the Source attribute to
user.userprincipalname. - Save your changes.
Microsoft AD FS (Active Directory Federation Services)
Procedure
- Open Server Manager and navigate to .
- In the left pane, expand AD FS and select Relying Party Trusts.
- Right-click your trust for Trend Vision One (The identifier usually starts with
https://signin.v1.trendmicro/saml...) and select Edit Claim Issuance Policy. - Select the rule responsible for sending the Name ID.
- Configure the rule as follows:
-
Claim rule template: Transform an Incoming Claim
-
Incoming claim type: UPN
-
Outgoing claim type: Name ID
-
Outgoing name ID format: Email
-
- Click Finish and then OK to save.
