ADFS for single sign-on
dont know if question being asked previously...
i have client having on-premises ad wants move mail account on exchange 2003 hosted exchange 2010... wants sso.. means wants users use same credentials use log-in domain computer access mails also. , should in sync client side ad always.
is possible adfs.. if yes please advice how.
client ad on xyz.com , hosted exchange ad abc.com .. need create trust between both domains also.
thanks
happiness always
jatin
yes believe both methods feasible. you can create trust allow authentication of domain users exchange servers or use adfs if trust creation isn't viable (both require action on behalf of ito hosting mailboxes).
you can use forest level (kerberos) trust or external trust. recommend using kerberos trust if possible eliminate potential issues ntlm on external trust (note external trust still try kerberos first; if ports opened resources, , domain established via fqdn, kerberos used).
for more on adfs, should starting point:
adfs how to
http://technet.microsoft.com/en-us/library/cc783520(ws.10).aspx
step step guide active directory federation services
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=15992
brandon wilson - premier field engineer (platforms)
Windows Server > Directory Services
Comments
Post a Comment