ADFS for single sign-on


dont know if question being asked previously...

i have client having on-premises ad wants move mail account on exchange 2003 hosted exchange 2010... wants sso.. means wants users use same credentials use log-in domain computer access mails also. , should in sync client side ad always.

is possible adfs.. if yes please advice how.

client ad on xyz.com , hosted exchange ad abc.com .. need create trust between both domains also.


thanks
happiness always
jatin

yes believe both methods feasible. you can create trust allow authentication of domain users exchange servers or use adfs if trust creation isn't viable (both require action on behalf of ito hosting mailboxes).

you can use forest level (kerberos) trust or external trust. recommend using kerberos trust if possible eliminate potential issues ntlm on external trust (note external trust still try kerberos first; if ports opened resources, , domain established via fqdn, kerberos used).

 

for more on adfs, should starting point:

 

adfs how to

http://technet.microsoft.com/en-us/library/cc783520(ws.10).aspx

 

step step guide active directory federation services

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=15992

 

 

 


brandon wilson - premier field engineer (platforms)


Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file