A. Register a custom Service Authorization Manager that implements Check Access. In this method, use System.Convert.ChangeType to transform the incoming claim set to a WindowsClaimSet type.
B. Apply a PrincipalPermission attribute on the operation with the required claims listed in the Roles property.
C. Within the operation, verify the presence of the required claims in the current AuthorizationContext.
D. Register an AuthorizationPolicy that maps external claims to an internal ClaimSet.