Active Directory Federation Services (AD FS) allows single sign-on access across organizational boundaries using claims-based authentication. AD FS maintains application security by implementing a claims-based authorization model where claims describe user identity attributes. Claims are held in authentication tokens that can be validated. With claims-based authentication, an external system authenticates a user and redirects them back to the application with claims about the user, allowing access if validated. Configuring AD FS in SharePoint 2013 requires setting up DNS, service accounts, certificates, and installing/configuring AD FS. AD FS version 3 improvements include reduced dependency on IIS, remote management, SQL replication, and a new Web Application Proxy for reverse proxy and AD FS proxy functionality.