question

AHamilton7416 avatar image
0 Votes"
AHamilton7416 asked piaudonn answered

WAP and ADFS on differant domains

I've setup an adfs that works well inside our network however there is a need now to use it to access a site from outside the domain. I was looking at setting up a WAP in our DMZ however the internal and external domain are different. Everything I've looked over states the internal and external domain have to be the same in order to get this working properly. Is there a was around this?

adfs
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

piaudonn avatar image
0 Votes"
piaudonn answered

The WAP servers do not have a requirement to be domain joined at all when they are solely used as ADFS Proxy servers.
You need to domain joined them only if you intend to publish non-claim aware applications using Kerberos constrained delegation. If not, they can even be in a workgroup.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.