SlideShare a Scribd company logo
SharePoint 2013 and
ADFS
MAXIM ZHVIRBLYA
EPAM SYSTEMS © 2014
Active Directory Federation Services
Active Directory Federation Services (AD FS) is a software component developed by Microsoft
that can be installed on Windows Server operating systems to provide users with single sign-on
access to systems and applications located across organizational boundaries. It uses a claims-
based access control authorization model to maintain application security and implement
federated identity.
Active Directory Federation Services
What is Claim?
Claim is piece of information that describes given identity on some aspect. Take claim as name-
value pair. Claims are held in authentication token that may have also signature so you can be
sure that token is not tampered on its way from remote machine to your system.
Claims-based authentication
Claims-based authentication is more general authentication mechanism that allows users to
authenticate on external systems that provide asking system with claims about user.
Claims-based authentication
1.User makes request to some application.
2.System redirects user to authentication page of external
system (it may also happen after system lets user to select
external system where he or she wants to log in).
3.After successful authentication external system redirects user
back with some information.
4.Application makes request to external system to validate user.
5.If user is valid then user gets access to application.
SharePoint 2013 ADFS Prerequisites
1) Create DNS Entry
2) Create a Service Account
3) Create ADFS Certificate Template
4) Request Certificates
Create DNS Entry
Create a Service Account
Create ADFS Certificate Template
Create ADFS Certificate Template
Request Certificates
Request Certificates
Certificates:
1. Service Communications
2. Token Decrypting
3. Token Signing
Installing AD FS v2
◦ download the ADFS 2.0 installation
Installing AD FS v2
◦ Right click “AdfsSetup.exe” and “Run as administrator”
◦ Click “Next >” on the “Welcome to the AD FS 2.0 Setup Wizard” screen
◦ Accept the terms of the license and click “Next >”
◦ On the “Server Role” screen select the “Federation server” radio button and click “Next >” to continue
◦ Click “Next >” on the “Install Prerequisite Software” screen
◦ Leave the “Start the AD FS 2.0 Management snap-in when this wizard closes.” checkbox selected and
click “Finish” to launch the post installation “AD FS 2.0 Federation Server Configuration Wizard”
Initial Configuration
Click the “AD FS 2.0 Federation Server Configuration Wizard” link
Select the “Create a new Federation Service” radio button and click “Next >”
Initial Configuration
Select the SSL certification that was previously created. For Service Communications
Specify the ADFS service account and password that was created during the prerequisite phase
Some Demo =)
AD FS V3?
Differences:
 AD FS is no longer dependent on IIS. This offers enhanced performance and reduces the foot print
of services, especially when AD FS is installed on Active Directory domain controllers.
Remote installation and configuration through Server Manager.
UI support for installing AD FS with SQL Server
Group Managed Service Account support. This enables AD FS to be run with service accounts
without managing expiring service account passwords.
SQL Server merge replication support when deploying AD FS across globally dispersed datacenters.
Note that in Windows Server® 2012 R2, the ‘stand-alone’ mode for AD FS setup has been removed.
Web Application proxy
Web Application proxy
Web Application Proxy – a new Remote Access role service in Windows Server® 2012 R2 - to
provide reverse proxy functionality for corporate web applications and services.
Web Application Proxy also functions as an AD FS proxy.
Questions & Discussion

More Related Content

PPTX
The Who, What, Why and How of Active Directory Federation Services (AD FS)
PPTX
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
PPTX
AD FS Workshop | Part 2 | Deep Dive
PPTX
Office 365-single-sign-on-with-adfs
PPTX
Extending SharePoint 2010 to your customers and partners
PPTX
2. Day 2 - Identify and SSO
PPTX
How to deploy SharePoint 2010 to external users?
The Who, What, Why and How of Active Directory Federation Services (AD FS)
Understanding Office 365’s Identity Solutions: Deep Dive - EPC Group
AD FS Workshop | Part 2 | Deep Dive
Office 365-single-sign-on-with-adfs
Extending SharePoint 2010 to your customers and partners
2. Day 2 - Identify and SSO
How to deploy SharePoint 2010 to external users?

What's hot (17)

PPTX
Adfs azure
PPTX
Understanding SharePoint Apps, authentication and authorization infrastructur...
PPTX
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
PPTX
OFM AIA FP Implementation View and Case Study
PPTX
SharePoint, ADFS and Claims Auth
PPTX
Adfs Shib Interop Um Oxford
PPTX
AD FS Workshop | Part 1 | Quick Overview
PPTX
O365-AzureAD Identity management
PPTX
Building Secure Extranets with Claims-Based Authentication #SPEvo13
PPTX
Office 365 Identity Management options
PPTX
Claims Based Authentication A Beginners Guide
PPTX
Office 365 api vs share point app model
PPTX
Claims Based Identity In Share Point 2010
PPTX
Session 3c The SF SaaS Framework
PPTX
Creating a Sign On with Open id connect
PPTX
OAuth in SharePoint 2013
PDF
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
Adfs azure
Understanding SharePoint Apps, authentication and authorization infrastructur...
SharePoint 2010 Extranets and Authentication: How will SharePoint 2010 connec...
OFM AIA FP Implementation View and Case Study
SharePoint, ADFS and Claims Auth
Adfs Shib Interop Um Oxford
AD FS Workshop | Part 1 | Quick Overview
O365-AzureAD Identity management
Building Secure Extranets with Claims-Based Authentication #SPEvo13
Office 365 Identity Management options
Claims Based Authentication A Beginners Guide
Office 365 api vs share point app model
Claims Based Identity In Share Point 2010
Session 3c The SF SaaS Framework
Creating a Sign On with Open id connect
OAuth in SharePoint 2013
SharePointFest 2013 Washington DC - SPT 103 - SharePoint 2013 Extranets: How ...
Ad

Viewers also liked (18)

DOCX
SharePoint 2013 REST API & Remote Authentication
PDF
SharePoint Permissions 101 (text)
PPTX
SharePoint 101 - Why? What? So what?
PPTX
Set up an SharePoint On-Premises environment for developing provider-hosted a...
PPTX
SharePoint Administration & Permissions
PPTX
Get > Set > Go On Sharepoint 2013
PPTX
SharePoint 2013 Site Administration
PPTX
Part II: SharePoint 2013 Administration by Todd Klindt and Shane Young - SPTe...
PPTX
Oauth and SharePoint 2013 Provider Hosted apps
PPTX
SharePoint Permissions 101
PPTX
Governance of content, permissions & apps in sharepoint 2013
PPTX
Part I: SharePoint 2013 Administration by Todd Klindt and Shane Young - SPTec...
PPTX
SharePoint PerformancePoint 101
PDF
IcingaCamp Stockholm - Graphing with Graphite und Grafana
RTF
Ruwana kimsa quechua i
PPT
Baber smith interview questions and answers
PPTX
Poliglotta 2014
PPT
B2 net interview questions and answers
SharePoint 2013 REST API & Remote Authentication
SharePoint Permissions 101 (text)
SharePoint 101 - Why? What? So what?
Set up an SharePoint On-Premises environment for developing provider-hosted a...
SharePoint Administration & Permissions
Get > Set > Go On Sharepoint 2013
SharePoint 2013 Site Administration
Part II: SharePoint 2013 Administration by Todd Klindt and Shane Young - SPTe...
Oauth and SharePoint 2013 Provider Hosted apps
SharePoint Permissions 101
Governance of content, permissions & apps in sharepoint 2013
Part I: SharePoint 2013 Administration by Todd Klindt and Shane Young - SPTec...
SharePoint PerformancePoint 101
IcingaCamp Stockholm - Graphing with Graphite und Grafana
Ruwana kimsa quechua i
Baber smith interview questions and answers
Poliglotta 2014
B2 net interview questions and answers
Ad

Similar to SharePoint 2013 and ADFS (20)

PPTX
Developing and deploying Identity-enabled applications for the cloud
PPTX
MCSA 70-412 Chapter 08
PDF
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
PPTX
Single Sign On using ADFS.pptx
PDF
ITPROCEED_TransformTheDatacenter_ten most common mistakes when deploying adfs...
PDF
Windows Server 2008 - Active Directory Components
PPT
Windows server 2003_r2
PDF
Federation Services
PPTX
Spsnj case study 2014
PPTX
MCSA 70-412 Chapter 04
PPTX
17 roles of window server 2008 r2
PPTX
teste
PPTX
Identity Management for Office 365 and Microsoft Azure
PPTX
Troopers 19 - I am AD FS and So Can You
PPTX
Adfs 2 & claims based identity
PDF
Spca2014 thvo adfs pub vochten
PPTX
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
PDF
Claims based identity second edition device
PPTX
Introduction to active directory and its services.pptx
PDF
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...
Developing and deploying Identity-enabled applications for the cloud
MCSA 70-412 Chapter 08
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
Single Sign On using ADFS.pptx
ITPROCEED_TransformTheDatacenter_ten most common mistakes when deploying adfs...
Windows Server 2008 - Active Directory Components
Windows server 2003_r2
Federation Services
Spsnj case study 2014
MCSA 70-412 Chapter 04
17 roles of window server 2008 r2
teste
Identity Management for Office 365 and Microsoft Azure
Troopers 19 - I am AD FS and So Can You
Adfs 2 & claims based identity
Spca2014 thvo adfs pub vochten
Upgrading AD from Windows Server 2003 to Windows Server 2008 R2
Claims based identity second edition device
Introduction to active directory and its services.pptx
Envision it SharePoint Extranet Webinar Series - Federation and SharePoint On...

Recently uploaded (20)

PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
A Presentation on Artificial Intelligence
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Modernizing your data center with Dell and AMD
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Encapsulation theory and applications.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
cuic standard and advanced reporting.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
KodekX | Application Modernization Development
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
Understanding_Digital_Forensics_Presentation.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
A Presentation on Artificial Intelligence
Review of recent advances in non-invasive hemoglobin estimation
Modernizing your data center with Dell and AMD
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Building Integrated photovoltaic BIPV_UPV.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Spectral efficient network and resource selection model in 5G networks
Encapsulation theory and applications.pdf
20250228 LYD VKU AI Blended-Learning.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
cuic standard and advanced reporting.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
KodekX | Application Modernization Development
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Empathic Computing: Creating Shared Understanding
Diabetes mellitus diagnosis method based random forest with bat algorithm

SharePoint 2013 and ADFS

  • 1. SharePoint 2013 and ADFS MAXIM ZHVIRBLYA EPAM SYSTEMS © 2014
  • 2. Active Directory Federation Services Active Directory Federation Services (AD FS) is a software component developed by Microsoft that can be installed on Windows Server operating systems to provide users with single sign-on access to systems and applications located across organizational boundaries. It uses a claims- based access control authorization model to maintain application security and implement federated identity.
  • 4. What is Claim? Claim is piece of information that describes given identity on some aspect. Take claim as name- value pair. Claims are held in authentication token that may have also signature so you can be sure that token is not tampered on its way from remote machine to your system.
  • 5. Claims-based authentication Claims-based authentication is more general authentication mechanism that allows users to authenticate on external systems that provide asking system with claims about user.
  • 6. Claims-based authentication 1.User makes request to some application. 2.System redirects user to authentication page of external system (it may also happen after system lets user to select external system where he or she wants to log in). 3.After successful authentication external system redirects user back with some information. 4.Application makes request to external system to validate user. 5.If user is valid then user gets access to application.
  • 7. SharePoint 2013 ADFS Prerequisites 1) Create DNS Entry 2) Create a Service Account 3) Create ADFS Certificate Template 4) Request Certificates
  • 13. Request Certificates Certificates: 1. Service Communications 2. Token Decrypting 3. Token Signing
  • 14. Installing AD FS v2 ◦ download the ADFS 2.0 installation
  • 15. Installing AD FS v2 ◦ Right click “AdfsSetup.exe” and “Run as administrator” ◦ Click “Next >” on the “Welcome to the AD FS 2.0 Setup Wizard” screen ◦ Accept the terms of the license and click “Next >” ◦ On the “Server Role” screen select the “Federation server” radio button and click “Next >” to continue ◦ Click “Next >” on the “Install Prerequisite Software” screen ◦ Leave the “Start the AD FS 2.0 Management snap-in when this wizard closes.” checkbox selected and click “Finish” to launch the post installation “AD FS 2.0 Federation Server Configuration Wizard”
  • 16. Initial Configuration Click the “AD FS 2.0 Federation Server Configuration Wizard” link Select the “Create a new Federation Service” radio button and click “Next >”
  • 17. Initial Configuration Select the SSL certification that was previously created. For Service Communications Specify the ADFS service account and password that was created during the prerequisite phase
  • 19. AD FS V3? Differences:  AD FS is no longer dependent on IIS. This offers enhanced performance and reduces the foot print of services, especially when AD FS is installed on Active Directory domain controllers. Remote installation and configuration through Server Manager. UI support for installing AD FS with SQL Server Group Managed Service Account support. This enables AD FS to be run with service accounts without managing expiring service account passwords. SQL Server merge replication support when deploying AD FS across globally dispersed datacenters. Note that in Windows Server® 2012 R2, the ‘stand-alone’ mode for AD FS setup has been removed. Web Application proxy
  • 20. Web Application proxy Web Application Proxy – a new Remote Access role service in Windows Server® 2012 R2 - to provide reverse proxy functionality for corporate web applications and services. Web Application Proxy also functions as an AD FS proxy.