Documente Academic
Documente Profesional
Documente Cultură
• AD FS Deployment Scenarios
• Deploying AD FS
• Implementing AD FS Claims
Lesson 1: Overview of AD FS
• What Is Identity Federation?
• AD FS Components
What Is Identity Federation?
Identity Federation:
Business-To-Business (B2B)
Business-To-Employee (B2E)
Business-To-Consumer (B2C)
Discussion: Identity Federation
Business Requirements
• What business requirements would lead to the deployment of an identity
federation solution?
What Is a Federation Trust?
Account Resource
Federation Federation Trust
Federation
Server Server
Federation
Service
Proxy
Domain
Controller
Web Server
running ADFS
Web Service
Agent
• AD FS Deployment Considerations
AD FS Deployment Options
Firewall
Firewall
Firewall
Firewall
Firewall
Firewall
Internet
Internet
AD DS AD DS
Account
federation
Federation
Trust Resource
Federation federation
Trust
Northwind Contoso
Traders
A. Datum Corp.
Federated Web SSO Web SSO
Firewall
Firewall
Forest
Trust
Internet
AD DS AD DS
Account
federation
Federation Resource
Trust federation
A. Datum Corp.
Federated Web SSO with Forest Trust
How AD FS Traffic Flows in a B2B Federation Scenario
Federated Web SSO
Federation Trust
7
Account
Resource
Federation
6 Federation
Server 10 Server
9
AD DS Domain 4
5 Controller
8 Internet
3
1 11
Client Web Server
How AD FS Traffic Flows in a B2E Federation Scenario
Federated Web SSO with Forest Trust
8
8
Account Federation
Proxy Sever 5
Account
Federation Federation
5 Trust Server
7
Internet 6
Resource Federation
4
Server
10
3
own domain
Controller
11
Separate AD
Domain
(AD FS Web Agent)
How AD FS Traffic Flows in a B2C Federation Scenario
4
7
Resource 6
Internet
Federation
Federation
Sever
3 Proxy Sever
5
2
Client 1
AD LDS Sever
(AD FS Web
Agent)
AD FS Deployment Considerations
AD FS scenario to be deployed
Certificate management
Directory store requirements
Application type
Manufacturer Supplier
• AD FS Prerequisites
• AD FS Certificate Requirements
•Token-signing Certificate
Federation Server
•Verification Certificate
Account Partners
Resource Partners
Trust Policy
Account Stores
ADFS-protected Applications
Organization Claims
What Is an AD FS Trust Policy?
Manufacturer Supplier
Resource
Account Partner
Partner
AD FS
Lesson 4: Implementing AD FS Claims
• What Are AD FS Claims?
AD FS Claims:
Identity Claims
Group Claims
Custom Claims
What Are Group and Custom Claims?
Account Resource
Partner Federated Namespace Partner
(Incoming/Outgoing)
Purchaser
Purchaser Organizational Claim
• Exercise 5: Configuring the Forest Trust and the Federated Trust Policies
Logon information
Virtual machine 6426A-NYC-DC1 6426A-CHI-DC1 6426A-NYC-CL1
Logon information
Password Pa$$w0rd