Link to home
Start Free TrialLog in
Avatar of ITADUMA
ITADUMA

asked on

Build Microsoft ADFS in New Environment and Decommission Old ADFS Environment

Hi, currently have two ADFS servers and two ADFS Proxy servers setup on our ESXi cluster in production and working.  The ESXi cluster is going away and have built new servers in Azure and joined the two ADFS servers to our domain and the ADFS Proxy servers are still in a work group.  My question is how do I go about getting the new ADFS farm and proxy server up and running with minimal downtime to the end users.  Any thoughts/insight would be great.
Avatar of Mahesh
Mahesh
Flag of India image

you want to deploy 2nd adfs farm or you want to upgrade adfs 2.0 to 3.0 or 3.0 to 4.0 or 2.0 to 4.0 ?

U need to provide more details?
Avatar of ITADUMA
ITADUMA

ASKER

Hi, thank for your reply.  I'm not sure if I need to deploy second farm.  My current farm is running as VMs in my ESXi cluster.  That cluster is going away and spun up servers in Azure which I eventually want to our new ADFS and ADFS proxy environment.  Please let me know if you need further clarification
what is your current ADFS server version?

It is 2008 R2 or 2012 OR 2012 R2 or 2016 ?

Each version has variant
Avatar of ITADUMA

ASKER

2012 R2 for both ADFS and ADFS proxy servers
what you can do, add new ADFS 2012 R2 in Azure as secondary servers in existing farm and make one of them primary and make current primary ADFs to secondary
After that uninstall ADFS role from current servers and if its defined anywhere in load balancers etc, remove it from there

To make azure adfs server primary and to make current primary to secondary
https://itworldjd.wordpress.com/2014/10/22/how-to-move-a-secondary-adfs-to-primary/
after that add two more proxy servers in azure and configure them as proxy and uninstall proxy from original proxy servers

you do need to update your external and internal dns records to point new adfs servers
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
If adfs is running with full SQL instance as database, then all adfs farm members are already act as primary  and then you don't need to make other sever primary and current to secondary, that step is applicable only if you are running with WID