Map User-Principal-Name to Name
This is a for those of you who notice a gap in the current RM Web Client ADFS configuration documentation. The documentation for the RM native client specifies the Relying Party claim rule should have the LDAP attribute User-Principle-Name mapped to the outgoing claim UPN. The Web Client documentation contains a simple custom rule but does not specify exactly which claims are are required. Unlike the native client the User-Principal-Name must be mapped to the outgoing claim Name, like this:
Some good news
In a an upcoming version we plan to support UPN for the web client, which will check UPN first and then Name, using whichever is sent by ADFS.