Provide SharePoint Single Sign-On with Active Directory Federation Services

  • January 27, 2009
  • By Dustin Hannifin
  • More Articles »

ADFS Deployment

If you were one of the early explorers of ADFS you probably remember that you performed most of the ADFS setup and configuration in Windows Server 2003 R2 using the Microsoft Management Console (MMC). That process required detailed guidance to ensure the configuration was done properly. Fortunately, ADFS setup in Windows Server 2008 has been greatly improved; it now uses configuration wizards for many of the components.

After properly planning your ADFS deployment, you can install your federation servers. To install a federation server, use the "Add Roles" wizard to add the Federation Service role (see Figure 3).


Figure 3. Adding the Federation Service Role: Use the "Add Roles" wizard to add a Federation Service role.

ADFS uses SSL for federation communication, so you'll need to obtain certificates via your own or third-party public-key infrastructure (PKI) providers. However, you can use self-signed certificates for test purposes and deployments (see Figure 4). When installing your federation server you will need both a Server Authentication Certificate and a Token Signing Certificate.


Figure 4. Selecting a Self-Signed Certificate: Because ADFS uses SSL, you'll need a certificate, but you can use a self-signed certificate for testing purposes.

You will need to install a Federation server on both your internal LAN and in your perimeter network. According to the design scheme (see Figure 2), the internal federation server acts as the account federation server, while the perimeter federation server acts as the resource federation server.

After installing the federation servers, you need to install the ADFS Web Agent on the SharePoint server (see Figure 5). Doing that lets the SharePoint server use federation claims for authentication.


Figure 5. Adding the ADFS Web Agent to the SharePoint Server: Use the "Add Roles" wizard to add the ADFS Web Agent to your SharePoint server.

ADFS Configuration

After completing the federation server installations, you need to configure the correct settings on each one. If you used the self-signed certification option above, you will also need to install the certificate into the trusted root CA store for the computer account for each federation server and for the SharePoint server.


Networking Solutions







Partners