Documente Academic
Documente Profesional
Documente Cultură
Directory
Christopher Chapman | MCT
Content PM, Microsoft Learning, PDG Planning ,
Microsoft
Microsof
t
Virtual
Click toAcadem
edit
Masterysubtitle
style
Module Overview
AD FS Overview
AD FS Deployment Scenarios
Configuring AD FS Components
Lesson 1: AD FS Overview
What Is Identity Federation?
What Are the Identity Federation Scenarios?
Benefits of Deploying AD FS
An identity federation:
Requires a trust relationship between two organizations or
entities
Allows organizations to retain control of:
Resource access
Their own user and group accounts
Federation
Federation for
for
business-to-consumer
business-to-consumer
or
or business-tobusiness-toemployee
employee in
in a
a Web
Web
single
single sign-on
sign-on
scenario
scenario
Federation
Federation
within
within an
an
organization
organization
across
across multiple
multiple
Web
Web
applications
applications
Benefits of Deploying AD FS
AD FS provides the following benefits:
Enables improved:
Security and control over authentication
Regulatory compliance
Interoperability with heterogeneous systems
Works with Active Directory Domain Services (AD DS) or Active
Directory Lightweight Directory Services (AD LDS)
Extends AD DS to the Internet
Demonstration: Installing AD FS
AD DS
Federation Trust
Account
Federation
Server
Account Partner
Organization
Web
Server
Resource
Federation
Server
Resource
Partner
Organization
PERIMETER
NETWORK
AD
DS
Account
Federati
on
Server
Contos
o
Resource
Federatio
n Server
Proxy
Account
Federatio
n Server
Proxy
Resource
Federation
Trust
AD FSenabled
Web
Server
Online
Retailer
Federatio
nServer
AD DS
3
3
Account
Federation
Server
Contos
o
1
1
Federation Trust
2
2
Web
Server
4
4
Resource
Federation
Server
Online
Retailer
Lesson 3: Configuring AD FS
Components
Description
UPN: indicates a Kerberos version 5 protocol-style
user principal name (UPN), for example:
user@realm
Identity
Group
Custom
2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered
trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of
Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a
commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT
MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.