Exchange and ADFS

yasser Mohamed AbdelMoneim 291 Reputation points
2022-03-26T10:09:50.037+00:00

Hello

I have Exchange 2016 hybrid with federated domain and 2 ADFS + 2 WAP servers .

I want to extend the whole setup to DR site , How can i do DR for ADFS and WAP servers?

what are the required setup for ADFS and DR in DR site and the changes required on Exchange servers?

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,503 questions
{count} votes

4 answers

Sort by: Most helpful
  1. yasser Mohamed AbdelMoneim 291 Reputation points
    2022-03-28T11:49:23.04+00:00

    Please specify the following:

    • Do you federate Exchange and ADFS directly for OWA, or do you have an Exchange Online environment and your AD FS to for all Office 365 workload, not only Exchange.

    Federation with all office 365 workload

    • What version of AD FS are you using?

    ADFS 2016

    • Is there any reason why you want to still use AD FS as opposed as other authentication methods which do not have the same challenges in terms of high availability?

    According security regulation , The security process should happen in Onprmise

    0 comments No comments

  2. yasser Mohamed AbdelMoneim 291 Reputation points
    2022-03-28T11:50:17.15+00:00

    Please find answers:

    • Federation with all office 365 workload
      • ADFS 2016
      • According security regulation , The security process should happen in Onprmise
    0 comments No comments

  3. Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
    2022-03-29T20:47:51.633+00:00

    By "security process" you mean authentication I suppose? PTA offers a way to keep the authentication on-premises without having to maintain an AD FS infrastructure: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta

    If you want to stay with AD FS, you can add multiple AD FS and WAP server to a farm. We do publish some guidance on how to install a part on that in Azure to increase your availability, you might want to have a look there:

    You might also want to consider monitoring the AD FS servers with Azure AD Connect Health agents: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-health-adfs.

    0 comments No comments

  4. yasser Mohamed AbdelMoneim 291 Reputation points
    2022-04-14T18:58:31.12+00:00

    So ADFS Farm can be extended through multiple AD sites?

    0 comments No comments