Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Implementing and Administering AD FS
Rating: 4.2 out of 5(158 ratings)
3,821 students

Active Directory: Implementing and Administering AD FS

Implementing and Administering AD FS
Created byVitalii Shumylo
Last updated 10/2025
English
English [Auto],

What you'll learn

  • Describe AD FS.
  • Explain how to deploy AD FS.
  • Explain how to implement AD FS for a single organization.
  • Explain how to extend AD FS to external clients.
  • Implement single sign-on (SSO) to support online services.

Course content

4 sections33 lectures3h 14m total length
  • Course Overview1:27

    Learn to implement and administer Active Directory Federation Services (AD FS) on Windows Server 2016, enabling single sign-on across local networks, external clients, and online applications.

  • Overview of AD FS. Section Overview2:45

    Explore how AD FS implements identity federation with federation trusts and claims-based identity, enabling secure single sign-on and web services across Active Directory domain services and organizations using https.

  • What is identity federation?4:42

    Enable identity federation across organizational and platform boundaries by establishing federated trusts, enabling authentication and authorization for shared resources over https, with defined credentials and privacy policies.

  • What are claims-based identity and claims-based authentication?4:08

    Explore how claims-based identity separates authentication from applications, using claims presented over https to authorize access based on user attributes like upn, email, and group membership.

  • Overview of web services8:08

    Explore web services standards for interoperable applications, including XML, SOAP, WS-Security, WS-Federation, and SAML, with AD FS authentication and token exchanges.

  • What is AD FS?5:48

    Discover how AD FS enables claims-based authentication across domains, acting as both identity provider and service provider. Explore features like web single sign on, WS-Federation interoperability, and extensible security architecture.

  • What’s new in AD FS in Windows Server 2016?4:54

    Explore the new AD FS features in Windows Server 2016, including LDAP v3 support and conditional access. Learn wizard-based management, delegated service management, and Azure multi-factor authentication integration.

  • How AD FS enables SSO in a single organization5:43

    Explore how AD FS enables single sign-on within an organization by using a federation server as both claims provider and relying party, with a web application proxy for external access.

  • How AD FS enables SSO in a business-to-business federation5:28

    Learn how AD FS enables single sign-on in a business-to-business federation by exchanging claims through federation trusts, tokens, and cookies.

  • Section overview. AD FS requirements and planning2:19

    Explore the prerequisites, components, and PKI requirements for deploying AD FS on Windows Server 2016, including federation server roles, high availability, capacity planning, and Web Application Proxy integration.

  • AD FS components4:59

    Explore the AD FS components, including federation server, federation server proxy and web application proxy, claims, claims rules, attribute store, claims provider, relying party trust, and certificates, enabling claims-based authentication.

  • AD FS requirements4:59

    Explore how the AD FS architecture delivers claims-based authentication by examining the federation server and proxy, duration servers, claims rules, attribute stores, claims providers, relying parties, tokens, and certificates.

  • PKI and certificate requirements8:24

    Learn how AD FS uses ssl certificates for service communication, token signing, and token decrypting, including options for self-signed, internal, or public certificates and the role of trusted authorities.

  • Federation server roles4:59

    Configure federation server roles, including claims provider and relying party, to issue and validate SAML tokens, using AD or AD LDS for claims, with a web application proxy for traffic.

  • Planning an AD FS deployment for online services10:47

    Plan an AD FS deployment for online services, enabling single sign-on across Azure and Microsoft online services, with AD FS, web application proxy, and Azure AD Connect for high availability.

  • Planning a highly available AD FS deployment5:53

    Plan high availability for AD FS federation servers and proxies, implement network load balancing, and use SQL Server clustering to ensure ongoing authentication for Office 365.

  • Capacity planning5:45

    Plan capacity for AD FS by evaluating expected usage, peak duration, and SSL access, using the capacity planning spreadsheet and estimation table to size federation servers and proxies.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

Active Directory Federation Services (AD FS) in the Windows Server 2016 operating system allows organizations to provide their users with the flexibility to sign in and authenticate to applications that exist on a local network, at a partner company, or in an online service. With AD FS, your organization can manage its own user accounts, and users have to remember only one set of credentials. Those credentials can provide access to a variety of applications, even when they reside at different locations.


Objectives

After completing this module, you will be able to:

· Describe AD FS.

· Explain how to deploy AD FS.

· Explain how to implement AD FS for a single organization.

· Explain how to extend AD FS to external clients.

· Implement single sign-on (SSO) to support online services.

Who this course is for:

  • Active Directory Administrators
  • ADFS Administrators
  • Windows Server Administrators