Link to home
Start Free TrialLog in
Avatar of SAM2009
SAM2009Flag for Canada

asked on

How to implement SSO?

Hi,

I just want to understand more about SSO. I know that is single sign on but which application or software should we install to implement SSO in AD environment?
Avatar of D Patel
D Patel
Flag of India image

You might need to install "AD FS 2.0"...
ASKER CERTIFIED SOLUTION
Avatar of Andy
Andy

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I think we are complicating things than it should be.  First question would be if your application is web based and if so, you could implement NTLM login.  If your application spans multiple servers then you could enable Kerberos.

If your application will be hosted in the cloud then ADFS would be an option and as far as WIF is concerned, it could be used for any scenario and is more complicated.
Avatar of SAM2009

ASKER

What is Salesforce SSO is a Microsft product or a third party tool?
Avatar of SAM2009

ASKER

But it uses for what? Do we need also a third party tool to make SSO works?
No it's configured between the application and your own identity provider (which AD FS provides for AD)
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of SAM2009

ASKER

One more question. I heard peoples say that  ADFS SSO authentication is case sensitive and they really complain about that. Is that true?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I would recommend AD FS 3.0 on 2012 R2 as it has better out of the box security.
There are lots of articles online regarding AD FS deployment, plan it correctly and it'll be a straightforward install. One of the best resources is the MS technet deployment guide:
https://technet.microsoft.com/en-us/library/dn486775(v=ws.11).aspx
Avatar of SAM2009

ASKER

Then why some applications using with adfs sso are not id case sensitive and some are?
I believe most are case sensitive, which ones aren't? and are they using ADFS SSO?
Avatar of SAM2009

ASKER

Like  Cisco Jabber is not case sensitive.
i think you'll find that the Federation ID is case-sensitive even with jabber!

Why does it matter is if it is case sensitive or not?
Avatar of SAM2009

ASKER

I just try to understand.
Fair enough, but I wouldn't worry about that too much.

In terms of AD FS, the MS technet article goes through it very well and should be a very good starting point, if not more, for designing the implementation.
Avatar of SAM2009

ASKER

Thanks to all for your help!