官术网_书友最值得收藏!

Identity and password-hash synchronization including ADFS integration

With the implementation of the federation, all authentication is retained on-premises, and all passwords are stored on-premises only. All authentication traffic is redirected from Azure AD to the on-premises ADFS, which authenticates the user against a trusted AD domain. This scenario is commonly used in different company sizes if SSO is required and password-hash synchronization is prohibited due to \ security reasons.

The requirement is the usage of a federation service provider, such as ADFS in addition to Azure AD Connect in a highly available deployment.

The following diagram shows the identity and password-hash synchronization with ADFS scenario:

Combine federation with password-hash synchronization

You can also combine the ADFS integration with password-hash synchronization to provide the capability if the on-premises infrastructure turns into an outage and users can still access their cloud services with their known password.

主站蜘蛛池模板: 曲沃县| 忻城县| 唐山市| 合作市| 都兰县| 临武县| 天祝| 遂宁市| 城步| 阜城县| 昌都县| 宜兰县| 武乡县| 锦州市| 米林县| 星子县| 田林县| 蒲城县| 宜黄县| 麦盖提县| 康平县| 平和县| 山阳县| 微博| 蚌埠市| 芦山县| 高清| 农安县| 库伦旗| 沁源县| 通许县| 根河市| 大厂| 中西区| 昭苏县| 宁陕县| 茶陵县| 晋江市| 溧水县| 积石山| 城口县|