Solved

ADFS 2.0 Farm setup

Posted on 2014-02-10
7
541 Views
Last Modified: 2014-11-12
Hello All,

I am planning on setting up an ADFS farm (Federated with Office 365) that will have as members our internal ADFS (Primary ADFS server already in place) and our DR server in the cloud. Both of the servers are Windows Server 2012 Standard.

My purpose is that in case our internet connectivity goes down, our ADFS will failover to my ADFS DR server located in the cloud and users will still be authenticated in the Office 365 portal.

Can someone help me on this?
0
Comment
Question by:LuiLui77
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39848310
You gonna use Azure for that? A good starting point is here:

http://technet.microsoft.com/library/dn509539.aspx
0
 

Author Comment

by:LuiLui77
ID: 39850273
Hi Vasilcho, Is there other options that I can use besides Azure?
0
 
LVL 40

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 39850942
Of course, but you mentioned the cloud, so I assumed Azure. Where are you planning to put it?

The principle is still the same, you need to bring one DC and (optionally now, as new versions dont have such restrictions), another server for the AD FS. You can also plan for Dirsync, but that is not really a critical component.

Again, good overview can be found in the Azure documentation:

http://technet.microsoft.com/en-us/library/dn509536.aspx
0
Instantly Create Instructional Tutorials

Contextual Guidance at the moment of need helps your employees adopt to new software or processes instantly. Boost knowledge retention and employee engagement step-by-step with one easy solution.

 

Author Comment

by:LuiLui77
ID: 39856111
Hey Vasilcho, I was not counting on the DC, I thought with the installation of AD lightweight in the same server where I want to install the secondary ADFS will do.

Can I do this?
0
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39856359
Won't you have a DC in the DR site? :)

AD FS 2.0 does NOT support AD LDS as the account store, AD FS 1.0 did.
0
 

Author Comment

by:LuiLui77
ID: 39856545
YIKES, ok.

Can I have ADFS 2.0 on a Domain Controller?

What I am thinking about doing is promoting the Cloud Server to be a Domain Controller.

Do you think this setup will work?
0
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39856661
AD FS 2.0/2.1? You can, but you shouldn't. It requires IIS to work, and I really doubt you or your security guy will like the idea. You can use RODC instead, but you will need to enable password caching on it for any user that needs to auth to AD FS.  

AD FS 3.0 which comes with 2012 R2 runs in the kernel and does not require IIS. You can look at that option too, but then you will probably have to rebuilt from scratch.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Nano Server Image Builder helps you create a custom Nano Server image and bootable USB media with the aid of a graphical interface. Based on the inputs you provide, it generates images for deployment and creates reusable PowerShell scripts that …
Azure Functions is a solution for easily running small pieces of code, or "functions," in the cloud. This article shows how to create one of these functions to write directly to Azure Table Storage.
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

697 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question