Is it safe to place the ADFS server in local network for claims-based application authentication.

Kane 76 Reputation points
2020-07-29T22:35:18.813+00:00

Hi;

I just created my first AD FS on Windows Server 2012 R2 on LAN which is used to authenticate the claims-based application on cloud which provided by my SaaS service provider.

I can authenticate with their application properly but they told me that they do not support ADFS Proxy, in this case; what is the best practice to secure my ADFS server. Currently; I have to do natting on firewall to allow inbound traffic to ADFS.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,222 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
    2020-07-30T12:47:21.167+00:00

    This claim makes no sense. What do they mean by they don't support ADFS Proxy (which is called Web Application Proxy [aka WAP] in Windows Server 2012 R2 by the way)? The SaaS is agnostic of the IDP infrastructure. Federation protocols in this scenario is entirely driven by the user. The application doesn't know if there is a proxy in the mix.
    Besides, WAP are not used when a user is connected from the LAN.

    We'll need to know a bit more about the infrastructure here to help you. So far, this doesn't make a lot of sense :(

    0 comments No comments