ADFS (Active Directory Federation Services)

I've been tasked with an ADFS project.

I have to find out if there are any risk of having ADFS facing the web without a proxy in front of it ?

Can someone let me know where I can find information about this type of concern and configuration ?

Thanks

Tech Guy :-)
andavispsavAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

btanExec ConsultantCommented:
This guidance is a good starter before even saying to go into deploying and configuring it. Actually you can still publish the ADFS server to internet (by opening port 443 like in case of Office365  or 80) to allow users outside your company network to access federation server. But security folks see it otherwise for such "direct" by external parties, and they consider proxy:
- Isolate federation servers such that it prevent external client computers from directly accessing prior authenticated
- Identify user identity and managed expectation with necessary sign-in experience for those from ext and int
- Leverage existing DMZ demarcated for consistent enforcement to service exposed such as web services via proxy
See more use case in
@ Planning Federation Server Proxy Placement
https://technet.microsoft.com/en-us/library/dd807130.aspx
@ Best Practices for Secure Planning and Deployment of AD FS
https://technet.microsoft.com/en-us/library/ff630160.aspx

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
andavispsavAuthor Commented:
I really appreciate this !!!

You've helped me greatly here and I do thank you.

Tech Guy :-)
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.