
Learn to implement and administer Active Directory Federation Services (AD FS) on Windows Server 2016, enabling single sign-on across local networks, external clients, and online applications.
Explore how AD FS implements identity federation with federation trusts and claims-based identity, enabling secure single sign-on and web services across Active Directory domain services and organizations using https.
Enable identity federation across organizational and platform boundaries by establishing federated trusts, enabling authentication and authorization for shared resources over https, with defined credentials and privacy policies.
Explore how claims-based identity separates authentication from applications, using claims presented over https to authorize access based on user attributes like upn, email, and group membership.
Explore web services standards for interoperable applications, including XML, SOAP, WS-Security, WS-Federation, and SAML, with AD FS authentication and token exchanges.
Discover how AD FS enables claims-based authentication across domains, acting as both identity provider and service provider. Explore features like web single sign on, WS-Federation interoperability, and extensible security architecture.
Explore the new AD FS features in Windows Server 2016, including LDAP v3 support and conditional access. Learn wizard-based management, delegated service management, and Azure multi-factor authentication integration.
Explore how AD FS enables single sign-on within an organization by using a federation server as both claims provider and relying party, with a web application proxy for external access.
Learn how AD FS enables single sign-on in a business-to-business federation by exchanging claims through federation trusts, tokens, and cookies.
Explore the prerequisites, components, and PKI requirements for deploying AD FS on Windows Server 2016, including federation server roles, high availability, capacity planning, and Web Application Proxy integration.
Explore the AD FS components, including federation server, federation server proxy and web application proxy, claims, claims rules, attribute store, claims provider, relying party trust, and certificates, enabling claims-based authentication.
Explore how the AD FS architecture delivers claims-based authentication by examining the federation server and proxy, duration servers, claims rules, attribute stores, claims providers, relying parties, tokens, and certificates.
Learn how AD FS uses ssl certificates for service communication, token signing, and token decrypting, including options for self-signed, internal, or public certificates and the role of trusted authorities.
Configure federation server roles, including claims provider and relying party, to issue and validate SAML tokens, using AD or AD LDS for claims, with a web application proxy for traffic.
Plan an AD FS deployment for online services, enabling single sign-on across Azure and Microsoft online services, with AD FS, web application proxy, and Azure AD Connect for high availability.
Plan high availability for AD FS federation servers and proxies, implement network load balancing, and use SQL Server clustering to ensure ongoing authentication for Office 365.
Plan capacity for AD FS by evaluating expected usage, peak duration, and SSL access, using the capacity planning spreadsheet and estimation table to size federation servers and proxies.
Learn to deploy AD FS in a single-organization setup, configure claims, claims rules, and both claims provider and relying party trusts, plus account and resource partners, and home realm discovery.
Explore AD FS claims and claim rules, including first claims, claim types, and relying party trusts, to define, transform, and authorize user access in AD FS deployments.
Configure a claims provider trust to identify the provider and define how the relying party consumes claims. Select federation data, file import, or manual setup, and install the SSL certificate.
Define a relying party trust to govern how the AD FS server interacts with applications, including claims rules, with three options: federation server import, file import, or manual configuration.
Install and configure AD FS by preparing the configuration database, SQL server, service accounts or gMSA, a trusted SSL certificate, and DNS records for a reliable federation server farm.
Configure account partner and resource partner in AD FS by establishing topology, adding an attribute store, creating relying party trusts, and building user claims into security tokens for federation.
Configure AD FS claims rules using templates to map attributes, apply filters and transformations, and enforce authorization rules for relying parties.
Configure claims rules with built-in templates, such as send ldap attribute as claims, group membership as a claim, and pass-through, transform, or deny access across relying parties.
Explain how home realm discovery redirects users to their home federation server for authentication, using either user selection or url parameters to determine the correct account partner.
Manage the AD FS certificate lifecycle to prevent expiration, including automatic rollover of token signing certificates, and monitor primary and secondary federation servers.
Learn to deploy and manage the web application proxy in Windows Server, publish applications securely, and ensure high availability for AD FS with certificates that contain the host name.
Discover how the web application proxy secures remote access to web apps by acting as a perimeter network reverse proxy and ADFS proxy with pre-authentication and SSL.
Explain how the web application proxy provides external access to AD FS through a reverse proxy in a perimeter network, using the same host name and certificates for seamless authentication.
Explore how the web application proxy acts as a reverse proxy in a perimeter network to protect internet-facing apps, using ADFs authentication, pre-authentication, or pass-through methods.
Publish each application via the web application proxy by configuring external and internal urls with a certificate for the external url; support split dns.
Install and configure the web application proxy on Windows Server 2012 R2 or later, including certificate management, load balancing, DNS configuration, and publishing the AD FS federation service.
Active Directory Federation Services (AD FS) in the Windows Server 2016 operating system allows organizations to provide their users with the flexibility to sign in and authenticate to applications that exist on a local network, at a partner company, or in an online service. With AD FS, your organization can manage its own user accounts, and users have to remember only one set of credentials. Those credentials can provide access to a variety of applications, even when they reside at different locations.
Objectives
After completing this module, you will be able to:
· Describe AD FS.
· Explain how to deploy AD FS.
· Explain how to implement AD FS for a single organization.
· Explain how to extend AD FS to external clients.
· Implement single sign-on (SSO) to support online services.