I need some clarification on passive ADFS claims. I have a requirement to block external access to OWA but still allow external access to Sharepoint Online. I'm not seeing any way to distinguish between the two in the claim request. Is this even possible?
The environment is ADFS 3.0 front-ended by a WAP.
Thanks,
Eric