Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

ADFS with two email domains.

Posted on 2016-09-22
2
Medium Priority
?
39 Views
Last Modified: 2016-10-11
Current setup: One AD domain with one ADFS server, and one ADFS proxy server. This ADFS setup is used for employees with an email domain of abc.com to access CRM. We would like to setup AD authentication for other employees in our company to access a different application, and their email domain is cde.com. The current ADFS server is setup with a certificate for the abc.com email domain.

My question is should I build an ADFS connection on the current server with cde.com, should I build an additional server and create an ADFS farm, or should I build an additional server but not in a farm (since the email domains are different)?

Thanks,
Bill
0
Comment
Question by:whbaxter
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
2 Comments
 
LVL 42

Accepted Solution

by:
Adam Brown earned 2000 total points (awarded by participants)
ID: 41811491
If these users are in the same Domain/Forest, the Email domain doesn't really matter so much. The certificate you have is still valid, you would just need to make sure the trust relationship between the new application and the ADFS server uses the URL on the certificate. For the most part, that certificate is just used for encrypting the connection to ADFS's HTTPS portal, so it doesn't normally get used for the actual ADFS functions. You can use the same ADFS server for both applications and email domains without a problem, it's just a more complex setup that requires you to include rules to exclude users that don't have the proper alias from connecting to the application they aren't supposed to use.
0
 
LVL 42

Expert Comment

by:Adam Brown
ID: 41838086
no response
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question