Mapping Your Deployment Goals to an AD FS Design
Applies To: Windows Server 2008
After you finish reviewing the existing Active Directory Federation Services (AD FS) deployment goals and you determine which goals are related to your deployment, you can map those goals to a specific AD FS design. For more information about AD FS predefined deployment goals, see Identifying Your AD FS Deployment Goals.
Use the following table to determine which AD FS design maps to the appropriate combination of AD FS deployment goals for your organization. This table refers only to the three primary AD FS designs, as described in this guide. However, you can create a hybrid or custom AD FS design by using any combination of the AD FS deployment goals to meet the needs of your organization.
AD FS deployment goal | Web SSO Design | Federated Web SSO Design | Federated Web SSO with Forest Trust Design |
---|---|---|---|
Provide Federated Access for Your Employees on the Corporate Network |
No |
Yes, in the account partner |
Yes, in the account partner |
Provide Federated Access for Your Remote Employees on the Internet |
No |
Yes, optional in the account partner |
Yes, optional in the account partner |
Provide SSO Access for Customers to Your Hosted Applications |
Yes |
No |
No |
No |
Yes, in the resource partner |
Yes, in the resource partner |