One thing you may encounter when sending through the role claim is that, if you use the built-in ADFS role claim, it will come through to us with a claim name of http://schemas.microsoft.com/ws/2008/06/identity/claims/role
. We require the claim name to just be 'role', so you may have to create a custom ADFS rule.