More info For further information, go to
https://aka.ms/i4jy7h
.
Windows 10 and Microsoft Passport integration
Microsoft Passport and AD FS have been designed to integrate to provide a further seamless
authentication experience for Windows 10 users.
Lightweight Directory Access Protocol (LDAP) integration to secure non-AD directories
Many organizations don’t rely on Active Directory for their identities. When this is the case, AD FS
will integrate into LDAP v3–compliant directories. This will allow further integration into the cloud
using those identity providers and the same enterprise experience when using Active Directory.
More info For further information, go to
https://aka.ms/qqupdh
.
Auditing improvements
Auditing in AD FS has been quite complicated in the past, with lots of verbose information that is
difficult to track. In Windows Server 2016, Microsoft has streamlined these improvements to prove
a more consistent auditing experience and provide easier methods to trace through the logs.
More info For further information, go to
https://aka.ms/ftbvm1
.
SAML 2.0 improvements
SAML support has been improved in Windows Server 2016 with the inclusion of importing trusts
based on metadata that contains multiple entities. With this support, you can configure AD FS to
participate in confederations such as InCommon Federations as well as other implementations
conforming to eGov 2.0.
More info For further information, go to
https://aka.ms/d1xw4q
.
Customized sign-in experience
In Windows Server 2016 you can customize messages, images, logos, and themes on a per
application basis, making it possible for multiorganizations to have one deployment rather than
multiple to suit the individual units. You can extend these customizations on a per–relying party
basis, as well.
130
CHAPTER 4 | Security and identity
More info For further information, go to
https://aka.ms/f6rxu8
.
Simplified password management for federated Office 365 users
AD FS can now send password expiry claims to relying party trusts. The application users will be
notified of their expiring passwords and then have the ability to take action and change their
passwords.
More info For further information, go to
https://aka.ms/i8jq9x
.
Configure access control policies without knowing the claim rules language
In Windows Server 2016, there are new access control policy templates which ease the
configuration of claims rules. These templates bring a simple UI-driven process to quickly and
securely create claims rules for the organization.
More info For further information, go to
https://aka.ms/rf833l
.
Migration from previous versions of AD FS
The upgrade process for AD FS has been greatly simplified in Windows Server 2016. Now, all
you need to do is install a Windows Server 2016 AD FS instance into an existing farm, verify the
functionality, and then remove the previous versions. AD FS in Windows Server 2016 can “act” like
a previous version of AD FS.
More info For further information, go to
https://aka.ms/qo74pk
.
Tell us
what you
think!
Is this book useful?
Did it meet your expectations?
Is there room for improvement?
Do'stlaringiz bilan baham: |