Solved

Help planning and understanding ADFS and Azure roll out.

Posted on 2015-02-12
4
73 Views
Last Modified: 2016-06-23
I am trying to better understand our needs in terms of ADFS, Azure, and everything else involved.  I am trying to understand at a high level what my options are, and what the best design would be.

Notes:
2008 R2 infrastructure w/ 1 forest & 1 domain
No on site exchange server, but use Office 365 for mail.

Needs:
I would like to setup SSO between our AD environment and Office365.  I would also like this integrated with our 3rd party cloud storage provider, 3rd party payroll company, etc.  Not to state the obvious, but I would like to have all users use a single password for all of these things.

I am trying to understand at a high level how to approach this, but I am still a little confused with the federated services environment as a whole.  Would it be best to setup my own ADFS server & proxy server?  Since we don't have any internal applications needing integration, would it be better to host ADFS locally or using Azure in the cloud?  Once AD & Office365 are integrated, would I want to integrate 3rd party apps with my local ADFS server, or Azure in the cloud?  If it helps we have the Office 365 Enterprise E1 plan currently.

Any advice you could give to help me grasp the needs and plan things out would be greatly appreciated.
0
Comment
Question by:spadmin1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 41

Assisted Solution

by:Vasil Michev (MVP)
Vasil Michev (MVP) earned 500 total points
ID: 40606733
You can run the AD FS servers on Azure VMs if that's what you mean, but I'd stick to an on-prem solution, if possible. I suggest you review the TechNet documentation in details:

https://technet.microsoft.com/en-us/library/dn509539.aspx
https://technet.microsoft.com/en-us/library/dn509516.aspx
0
 

Author Comment

by:spadmin1
ID: 40616856
We run Office365/Exchange up in the cloud.  If we had an on site AD FS server, would I still need to setup Azure VM's for Office365 SSO?  All of the documentation I have been looking at indicates I would need to do so.  Or would I get to use the free "Azure" portion of our Enterprise E1 Office 365 plan?
0
 
LVL 41

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 40617063
The "Azure" portion of O365 is Azure AD, it has nothing to do with hosting VMs or similar. You will have to purchase a separate Azure subscription and provision the VMs there. If you want to place the AD FS infra in Azure that is, otherwise just run it on prem.

You can also just use dirsync with password sync as alternative, it's actually the recommended setup for smaller shops.
0

Featured Post

The Ultimate Checklist to Optimize Your Website

Websites are getting bigger and complicated by the day. Video, images, custom fonts are all great for showcasing your product/service. But the price to pay in terms of reduced page load times and ultimately, decreased sales, can lead to some difficult decisions about what to cut.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article demonstrates probably the easiest way to configure domain-wide tier isolation within Active Directory. If you do not know tier isolation read https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/s…
Microsoft is moving in-place eDiscovery & hold from ECP to EOP console under Content Search in Search and Investigation Options.  In this post, I will be showing you how to export emails to a PST file using the Content Search Options.
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question