Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to Set up ADFS

Most organizations today have hybrid environments where they use on-premises applications as well as cloud software. ADFS offers single sign-on to users where they will be authenticated by Active directory just once and then they will be allowed to access all the federated applications easily. ADFS' token system is more secure than signing into each application separately, and it also helps that users don't need to remember multiple passwords.

Download for Free
Free, fully functional 30-day trial
  • Here is how to configure AD FS on your domain controller.

  • Step 1: Add ADFS role to the Domain Controller
  • To add ADFS as a role, open Server Manager, and navigate to Manage > Add Roles and Features. Click Next, to open the Add Roles and Features Wizard.

  • Select Role-based and Feature-based installation and click Next.

  • In the Server Selection step, choose Select a server from the server pool and click Next.

  • From the server roles list, select Active Directory Federation Services and click Next.

  • In the next step, select .Net Framework 4.5 Features and click Next and Next again.

  • Click Install.

  • Once the feature installation process is over, click Close.

  • Step 2: Post-deployment configuration
  • Go back to Server Manager and look for the Notifications tab on the right side.Click the message Configure the federation service on this server.

  • In the Configuration Wizard, select Create the first federation server in a federation server farm.

  • In the next step, select your account to perform federation service configuration.

  • In the next window, you will be asked to add the SSL certificate, Federation Service Name and Federation Service Display Name. You can select a certificate from the ones installed on the server or make one yourself. The certificate has to be in .PPX format. Federation Service Name is the FQDN of your AD FS and you can enter a display name of your choice. Click Next.

  • Note: Make sure that the FQDN of your ADFS has been updated in the DNS.

  • Specify a service account. You can either manually create one in the Wizard or go to Windows PowerShell for the Wizard to create one for you.

  • Follow the steps to create the service account. Then enter the name of your group managed service account in the space given and click Next.

  • In the Specify Database section, you are given the option to choose between a WID database or an SQL database. If yous is a small organization, then use WID. Otherwise, go for SQL.

  • In the next section, you will be asked to review the settings. If everything looks okay, click Next.

  • In the next window, click on Configure. And then, close the Wizard.

  • Step 3: Confirm that ADFS is functional
  • Use Set-AdfsProperties cmdlet on PowerShell to enable ldp-initiated Sign-on.

  • Open a web browser and copy this link - https://ADFS_FQDN/adfs/ls/idpinitiatedSignOn.aspx

  • You should see the name of your domain and be able to successful sign in.

  • You have successfully configured AD FS on your domain controller.

    ADAudit Plus is a real-time Active Directory auditing and reporting tool that has a n exclusive section for ADFS audit reports. This section has reports on logon successes, logon failures and extranet lockouts and so on. These reports can help troubleshoot problems with account lockouts and also detect any malicious interference in the network. These reports are only a part of the over 200 pre-packaged audit reports that can be generated in a few clicks.

Request 1-on-1 demo

  •  
  •  
  •  
  •  
  •  
  • -Select-
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.

Thanks

One of our solution experts will get in touch with you shortly.

ADAudit Plus Trusted By