Hello there,
In an Active Directory Federation Services (ADFS) setup, access to relying party trusts is often controlled by claim rules. These claim rules determine what claims are issued in the security token for a user when they authenticate through ADFS. If users are getting access to resources that they shouldn't, it's likely due to the claim rules being configured incorrectly.
Hope this resolves your Query !!
--If the reply is helpful, please Upvote and Accept it as an answer--