Q. How many Active Directory Federation Service (ADFS) servers do I need in a multi-domain environment?
October 7, 2009
A. ADFS works well with trusts, so the answer depends on the trusts between the domains. Essentially, the ADFS server has to be able to query the user account to populate the claims information.
A single ADFS server can service all domains in a forest (because all domains in a forest have bi-directional, transitive trusts). In addition, a single ADFS server could service all domains and forests that have a trust relationship. If you have forests without trusts, you need one ADFS server for each forest.
Related Reading:
Q. What are the server roles in Windows Server 2008?
How ADFS "Does" Identity Federation
Check out hundreds more useful Q&As like this in John Savill's FAQ for Windows. Also, watch instructional videos made by John at ITTV.net.
About the Author
You May Also Like