Implement claims-based authentication: internal access

Enabling claims-based authentication for internal access to Dynamics 365 Server data involves the following steps:

  1. Deploy and configure AD FS.

  2. Configure the Dynamics 365 Customer Engagement (on-premises) server for claims-based authentication.

  3. Configure the AD FS server for claims-based authentication.

  4. Test internal claims-based authentication.

Claims-based authentication is not a requirement for intranet Dynamics 365 Server access. However, claims-based authentication is required for Dynamics 365 Customer Engagement (on-premises) IFD access.

Known issue

“An error occurred. Please try again or contact your system administrator if error persists” message returned in app and sitemap designers

When IFD is enabled, you can’t access the app designer or sitemap designer of a Unified Interface app using the IFD configured internal URL, such as https://internalcrm.contoso.com/orgname. You must use the external URL that has been configured for IFD such as https://orgname.contoso.com.