Active Directory Federation Services Experts

Web Single Sign On via Active Directory
Miles Consulting Corp's Active Directory consultants use Active Directory Federation Services (FS) to provides Web-based single sign-on (SSO) technologies to authenticate a user to multiple Web applications over the life of a single online session. Active Directory Federation Services securely shares digital identity and entitlement rights, or "claims," across security and enterprise boundaries.
Federation Scenarios
Federated Web SSO with Forest Trust Web SSO Federated Web SSO
Forests located in the DMZ and Internal network. A federation trust is estabilished so accounts in Internal forest can access Web based applications in perimeter network (including Intranet or Internet access) Users must authenticate only once to access multiple Web based applications. All users are external, and no federation trust exists. Federation trust relationship estabilished between two businesses. FS routes authentication requires from user accounts in "adatum" to Web based applications that are located in "tryresearch" network.
AD FS Authentication Flow
Client tries to access Web application in tryresearch.net. Web server requests token for access.
Client redirects to Federation Server on tryresearch.net. Federation server has list of partners that have access to the Web application. Refers client to its adatum.com Federation server.
Instruct client to get a token from adatum.com Federation Server.
Client is member of its domain. Presents user authentication data to adatum.com Federation Server.
Based on authentication data. SAML token generated for the client.
User obtains SAML token from adatum.com Federation Server for tryresearch.net Federation Server.
Redirects client to tryresearch.net federation Server for claims management.
Based on policies for the claims presented by the adatum.com, a tryresearch.net token for the Web application is generated for the client.
The treyresearch.net token is delivered to client.
Client can now present tryresearch.net token to Web server to gain access to the application.
© 2010 Miles Consulting Corp | Sitemap | Legal