Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / IIS / IIS Security / August 2006

Tip: Looking for answers? Try searching our database.

Should ADFS be implemented when...

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
JackBlack - 21 Aug 2006 21:27 GMT
Should ADFS (Federation Services) be implemented in a network where web
applications running on member servers requires access to a) domain-based
SQL Servers, b) domain-based Exchange servers, and c) AD object info (such
as user addresses, departments, groups, etc)?

Trying to nail down where exactly (and IF) I need the Federation Services on
our domain controllers...

Thanks!
Jack
Roger Abell [MVP] - 24 Aug 2006 04:19 GMT
The main use case for ADFS in its current, initial release
is for interop between different authentication realms, such
as the forests of two corps, where the objective is to provide
webservices one to the other or both to each other, but, and
this is key, where the authetication and authorization to use is
unrepudiatable responsibility of the using realm once policy has
defined what the used party agrees to provide and the parties
agree on how those services are accessed.

Long words.  If I agree to provide services X to your users,
but I do not want to define accounts for your users, nor to be
responsible for authenticating that your users are who they claim,
and I want you to be responsible for your use of the provided
service, of the accounts you allow to use them, etc. so that I can
hold you responsible for the uses made by your access, then
ADFS fits the bill like little else can.

This use model is probably overkill for the cases you have described.
I can see how with an ADAM install on the machines without AD,
and providing them with an STS install, you feasibly could squeeze
the scenarios you mentioned into an ADFS model.  It would however
be pretty complicated for what it accomplishes.

Also the present form of ADFS is that it is for web scenarios
exclusively, and, when used in a domain does not need to be
installed on the domain controllers.

> Should ADFS (Federation Services) be implemented in a network where web
> applications running on member servers requires access to a) domain-based
[quoted text clipped - 6 lines]
> Thanks!
> Jack
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2010 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.