<Objs Version="1.1.0.1" xmlns="http://schemas.microsoft.com/powershell/2004/04">
  <Obj RefId="0">
    <TN RefId="0">
      <T>Microsoft.IdentityServer.PowerShell.Resources.RelyingPartyTrust</T>
      <T>System.Object</T>
    </TN>
    <ToString>Microsoft.IdentityServer.PowerShell.Resources.RelyingPartyTrust</ToString>
    <Props>
      <B N="AutoUpdateEnabled">false</B>
      <S N="DelegationAuthorizationRules"></S>
      <Obj N="EncryptionCertificateRevocationCheck" RefId="1">
        <TN RefId="1">
          <T>Microsoft.IdentityServer.PolicyModel.Configuration.RevocationSetting</T>
          <T>System.Enum</T>
          <T>System.ValueType</T>
          <T>System.Object</T>
        </TN>
        <ToString>CheckChainExcludeRoot</ToString>
        <I32>5</I32>
      </Obj>
      <S N="IssuanceAuthorizationRules">@RuleTemplate = "AllowAllAuthzRule"_x000D__x000A_ =&gt; issue(Type = "http://schemas.microsoft.com/authorization/claims/permit", Value = "true");_x000D__x000A__x000D__x000A_</S>
      <Obj N="SigningCertificateRevocationCheck" RefId="2">
        <TNRef RefId="1" />
        <ToString>CheckChainExcludeRoot</ToString>
        <I32>5</I32>
      </Obj>
      <Nil N="WSFedEndpoint" />
      <S N="IssuanceTransformRules">@RuleName = "Name Uniqueness"_x000D__x000A_c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]_x000D__x000A_ =&gt; issue(store = "Active Directory", types = ("http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"), query = ";mail;{0}", param = c.Value);_x000D__x000A__x000D__x000A_@RuleTemplate = "MapClaims"_x000D__x000A_@RuleName = "Email to NameID"_x000D__x000A_c:[Type == "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"]_x000D__x000A_ =&gt; issue(Type = "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier", Issuer = c.Issuer, OriginalIssuer = c.OriginalIssuer, Value = c.Value, ValueType = c.ValueType, Properties["http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/format"] = "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress");_x000D__x000A__x000D__x000A_@RuleTemplate = "LdapClaims"_x000D__x000A_@RuleName = "Robin Attributes"_x000D__x000A_c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"]_x000D__x000A_ =&gt; issue(store = "Active Directory", types = ("FirstName", "LastName", "Email"), query = ";givenName,sn,mail;{0}", param = c.Value);_x000D__x000A__x000D__x000A_</S>
      <Obj N="ClaimsAccepted" RefId="3">
        <TN RefId="2">
          <T>Microsoft.IdentityServer.PowerShell.Resources.ClaimDescription[]</T>
          <T>System.Array</T>
          <T>System.Object</T>
        </TN>
        <LST />
      </Obj>
      <B N="ConflictWithPublishedPolicy">false</B>
      <B N="EncryptClaims">true</B>
      <B N="Enabled">true</B>
      <Nil N="EncryptionCertificate" />
      <Obj N="Identifier" RefId="4">
        <TN RefId="3">
          <T>System.Collections.ObjectModel.ReadOnlyCollection`1[[System.String, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]]</T>
          <T>System.Object</T>
        </TN>
        <LST>
          <S>https://robinpowered.com</S>
        </LST>
      </Obj>
      <DT N="LastMonitoredTime">1900-01-01T00:00:00+00:00</DT>
      <Nil N="LastPublishedPolicyCheckSuccessful" />
      <DT N="LastUpdateTime">1900-01-01T00:00:00+00:00</DT>
      <Nil N="MetadataUrl" />
      <B N="MonitoringEnabled">false</B>
      <S N="Name">Robin Powered</S>
      <I32 N="NotBeforeSkew">0</I32>
      <Nil N="Notes" />
      <S N="OrganizationInfo"></S>
      <S N="ImpersonationAuthorizationRules">c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid", Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$" ] =&gt; issue(store="_ProxyCredentialStore",types=("http://schemas.microsoft.com/authorization/claims/permit"),query="isProxySid({0})", param=c.Value );_x000D__x000A_c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid", Issuer =~ "^(AD AUTHORITY|SELF AUTHORITY|LOCAL AUTHORITY)$" ] =&gt; issue(store="_ProxyCredentialStore",types=("http://schemas.microsoft.com/authorization/claims/permit"),query="isProxySid({0})", param=c.Value );_x000D__x000A_c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/proxytrustid", Issuer =~ "^SELF AUTHORITY$" ] =&gt; issue(store="_ProxyCredentialStore",types=("http://schemas.microsoft.com/authorization/claims/permit"),query="isProxyTrustProvisioned({0})", param=c.Value );</S>
      <S N="ProtocolProfile">WsFed-SAML</S>
      <Obj N="RequestSigningCertificate" RefId="5">
        <TN RefId="4">
          <T>System.Collections.ObjectModel.ReadOnlyCollection`1[[System.Security.Cryptography.X509Certificates.X509Certificate2, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]]</T>
          <T>System.Object</T>
        </TN>
        <LST />
      </Obj>
      <B N="EncryptedNameIdRequired">false</B>
      <B N="SignedSamlRequestsRequired">false</B>
      <Obj N="SamlEndpoints" RefId="6">
        <TN RefId="5">
          <T>Microsoft.IdentityServer.PowerShell.Resources.SamlEndpoint[]</T>
          <T>System.Array</T>
          <T>System.Object</T>
        </TN>
        <LST>
          <Obj RefId="7">
            <TN RefId="6">
              <T>Microsoft.IdentityServer.PowerShell.Resources.SamlEndpoint</T>
              <T>System.Object</T>
            </TN>
            <ToString>Microsoft.IdentityServer.PowerShell.Resources.SamlEndpoint</ToString>
            <Props>
              <S N="Binding">POST</S>
              <URI N="BindingUri">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</URI>
              <I32 N="Index">0</I32>
              <B N="IsDefault">false</B>
              <URI N="Location">https://dashboard.robinpowered.com/sso/saml/custom</URI>
              <S N="Protocol">SAMLAssertionConsumer</S>
              <Nil N="ResponseLocation" />
            </Props>
          </Obj>
        </LST>
      </Obj>
      <S N="SamlResponseSignature">AssertionOnly</S>
      <S N="SignatureAlgorithm">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</S>
      <I32 N="TokenLifetime">60</I32>
    </Props>
  </Obj>
</Objs>