官术网_书友最值得收藏!

Identity and password-hash synchronization including ADFS integration

With the implementation of the federation, all authentication is retained on-premises, and all passwords are stored on-premises only. All authentication traffic is redirected from Azure AD to the on-premises ADFS, which authenticates the user against a trusted AD domain. This scenario is commonly used in different company sizes if SSO is required and password-hash synchronization is prohibited due to \ security reasons.

The requirement is the usage of a federation service provider, such as ADFS in addition to Azure AD Connect in a highly available deployment.

The following diagram shows the identity and password-hash synchronization with ADFS scenario:

Combine federation with password-hash synchronization

You can also combine the ADFS integration with password-hash synchronization to provide the capability if the on-premises infrastructure turns into an outage and users can still access their cloud services with their known password.

主站蜘蛛池模板: 宜君县| 边坝县| 南溪县| 滦平县| 长武县| 兴仁县| 荣成市| 万荣县| 镇安县| 福建省| 泰和县| 黔东| 冕宁县| 绥芬河市| 龙里县| 郓城县| 蓬安县| 乌兰察布市| 黎城县| 三江| 龙州县| 三河市| 永定县| 揭西县| 马公市| 扶风县| 哈密市| 巨鹿县| 阿尔山市| 太和县| 苏尼特左旗| 昆山市| 嵊州市| 含山县| 黎川县| 农安县| 崇礼县| 西贡区| 健康| 阜城县| 贵溪市|