MS-50412 - Implementing Active Directory Federation Services 2.0 for Windows Server 2008



Similar documents
50412: Implementing Active Directory Federation Services 2.0

MS Configure and Troubleshoot Identity Access Solutions with Windows Server 2008 Active Directory

Course Active Directory Services with Windows Server

Active Directory Services with Windows Server 10969B; 5 days, Instructor-led

Microsoft Active Directory Services with Windows Server

Course 10969A Active Directory Services with Windows Server

Active Directory Services with Windows Server

Course 6426: Configuring and Troubleshooting Identity & Access Solutions With Windows Server 2008 Active Directory Page 1 of 6

Table of Contents. Introduction. Audience. At Course Completion

Active Directory Services with Windows Server MOC 10969

Configuring Advanced Windows Server 2012 Services

Configuring and Troubleshooting Identity and Access Solutions with Windows Server 2008 Active Directory Course 6426C: Three days

Module 2: Deploying and Managing Active Directory Certificate Services

6436: Designing a Windows Server 2008 Active Directory Infrastructure and Services (5 Days)

Course: Fundamentals of Microsoft Server 2008 Active Directory

Configuring Advanced Windows Server 2012 Services Course# 20412D

Active Directory Services with Windows Server

Table of Contents. Introduction. Audience. At Course Completion

Configuring Advanced Windows Server 2012 Services

MOC 6436A: Designing Active Directory Infrastructure and Services in Windows Server 2008

Configuring Advanced Windows Server 2012 Services 5 Days

MS Configuring Advanced Windows Server 2012 Services

MOC ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER

20417-Upgrading Your Skills to MCSA Windows Server 2012

LEARNING SOLUTIONS website milner.com/learning phone

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

Configuring and Troubleshooting Identity and Access Solutions with Windows Server 2008 Active Directory

Course 20412A: Configuring Advanced Windows Server 2012 Services

Course Outline. Course 20412B: Configuring Advanced Windows Server 2012 Services. Duration: 5 Days

Configuring Advanced Windows Server 2012 Services

MS 20417B: Upgrading Your Skills to MCSA Windows Server 2012

Microsoft Dynamics CRM 2011 Installation and Deployment

Configuring Advanced Windows Server 2012 Services MOC 20412

Administering the Web Server (IIS) Role of Windows Server

Upgrading Your Skills to MCSA Windows Server 2012

Microsoft Dynamics 2011: MS Installation and Deployment

Designing Windows Server 2008 Active Directory Infrastructure and Services Course 6436B; 5 Days, Instructor-led

Administering the Web Server (IIS) Role of Windows Server 10972B; 5 Days

MS 10972A Administering the Web Server (IIS) Role of Windows Server

Active Directory Services with Windows Server

MS-6416D: Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

MCITP MCITP: Enterprise Administrator on Windows Server 2008 (5 Modules)

MCSA/MCITP: Enterprise Windows Server 2008 Course 9952; 14 Days, Instructor-led

10972-Administering the Web Server (IIS) Role of Windows Server

DottsConnected SHAREPOINT 2010 ADMIN TRAINING. Exercise 1: Create Dedicated Service Accounts in Active Directory

Windows Server. Introduction to Windows Server 2008 and Windows Server 2008 R2

Preliminary Course Syllabus

"Charting the Course... MOC D Configuring Advanced Windows Server 2012 Services Course Summary

MS Design, Optimize and Maintain Database for Microsoft SQL Server 2008

Designing a Windows Server 2008 Active Directory Infrastructure and Services

10972B: Administering the Web Server (IIS) Role of Windows Server

NOTE: Labs in this course are based on the General Availability release of Windows Server 2012 R2 and Windows 8.1.

NE-6416D Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

Designing a Windows Server 2008 Applications Infrastructure

Upgrading Your Skills to MCSA Windows Server 2012

Course MS20696A Managing Enterprise Devices and Apps using System Center Configuration Manager

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Updating Your Network Infrastructure and Active Directory Technology Skills to Windows Server 2008

Course 6437A: Designing a Windows Server 2008 Applications Infrastructure

Build Your Knowledge!

Course Syllabus. 2553A: Administering Microsoft SharePoint Portal Server Key Data. Audience. At Course Completion.

Managing Enterprise Devices and Apps using System Center Configuration Manager 20696B; 5 Days, Instructor-led

NIIT Education and Training, Doha, Qatar - Contact: /1798;

M6430a Planning and Administering Windows Server 2008 Servers

Deploying and Managing a Public Key Infrastructure

MS 20342B: Advanced Solutions of Microsoft Exchange Server 2013

AV-006: Installing, Administering and Configuring Windows Server 2012

Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop

Course: Configuring and Troubleshooting Windows Server 2008 Active Direct-ory Domain Services

M6425a Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MS Implementing an Advanced Server Infrastructure

Implementing and Administering Security in a Microsoft Windows Server 2003 Network

Build Your Knowledge!

6445A - Implementing and Administering Small Business Server 2008

Deploying Microsoft Windows Rights Management Services

Implementing an Advanced Server Infrastructure

Administering Windows Server 2012

Configuring Managing and Maintaining Windows Server 2008 Servers (6419B)

MS 20341B: Core Solutions of Microsoft Exchange Server 2013

Lab : Planning and Implementing a Virtual Machine Deployment and Management Strategy

Managing Enterprise Devices and Apps using System Center Configuration Manager

ABOUT THIS COURSE AT COURSE COMPLETION PREREQUISITES COURSE OUTLINE. Core Solutions of Microsoft Exchange Server 2013 Duration : 5 days

Designing a Windows Server 2008 Active Directory Infrastructure and Services

Designing a Windows Server 2008 Applications Infrastructure

Configuring, Managing and Maintaining Windows Server 2008 Servers

Upgrading Your Skills to MCSA Windows Server 2012

6419: Configuring, Managing, and Maintaining Server 2008

Transcription:

MS-50412 - Implementing Active Directory Federation Services 2.0 for Windows Server 2008 Table of Contents Introduction Audience Prerequisites At Course Completion Student Materials Course Outline Introduction This four-day instructor-ledcourse provides students with the knowledge and skills to install and configure Active Directory Federation Services 2.0 (AD FS). The course focuses on terminology, user interfaces, and common configuration scenarios for AD FS. Students will learn how to design AD FS environments and supporting technology such as a Public Key Infrastructure. Students will also learn how to design AD FS for security and high availability. Audience This course is intended for Windows IT professionals who want to become Active Directory Federation Services (AD FS) enterprise administrators, and move into the role of designing AD FS environments. Prerequisites Before attending this course, students must have familiarity with the following technologies and concepts: Basic understanding of networking. Intermediate understanding of network operating systems. An awareness of security best practices. Basic knowledge of server hardware. Some experience creating objects in Active Directory. Foundation course (6424) or equivalent knowledge. Basic concepts of backup and recovery in a Windows Server Environment. At Course Completion At the end of this course, the student will be able to: Define key concepts and terminology relating to Active Directory Federation Services 2.0. Install and configure Windows prerequisites for AD FS 2.0. Install and configure Public Key Infrastructure (PKI) for AD FS 2.0. Deploy AD FS 2.0 to provide claims-aware authentication in a single organization. Configure AD FS 2.0 to provide claims-aware authentication in a business-to-business federation. Design and deploy advanced AD FS 2.0 scenarios, including providing for high availability and SAML interoperability. Use the AD FS 2.0 claims rule language to create custom claim rules. Troubleshoot AD FS 2.0.

Student Materials The student kit includes a comprehensive workbook and other necessary materials for this class. Course Outline Module 1: Introducing Claims-based Identity This module explains how to recognize AD FS terminology and common use cases for AD FS 2.0. Introducing the Identity Metasystem Existing Solutions for Managing Identities The Benefits of Claims-based Identity The Evolution of AD FS Use Cases for AD FS AD FS and Claims-based Terminology Lab : Familiarizing Yourself with the Lab Environment Accessing Servers Using Hyper-V Accessing Servers Using Remote Desktop Discuss and describe the Seven Laws of Identity, and how they pertain to managing identities for users and applications. Examine existing solutions for managing identities. Describe the benefits of the Claims-based Identity model. Discuss the evolution of Active Directory Federation Services (AD FS). Describe common use cases for AD FS. Discuss common terminology used when working with AD FS and Claims-based Identity. Module 2: AD FS Prerequisites This module explains how to configure Windows prerequisites for AD FS 2.0, including Windows Server and Internet Information Services (IIS). This module also explains how AD FS 2.0 utilizes Web services to achieve interoperability. Windows Prerequisites Introducing Directory Services Active Directory and Active Directory Lightweight Directory Services Web Services, Standards, and Interoperability Internet Information Services Lab : Installing Windows Prerequisites for AD FS 2.0 Configuring DNS Forwarders Configure a Sample WIF Application Identify the key Windows components required for AD FS. Describe the key characteristics of a Directory Service. Describe the role Active Directory and AD LDS perform in an AD FS deployment. Describe what is meant by the terms Web Services, WS-*, and Security Assertion Markup Language (SAML). Recognize the role of IIS in a successful AD FS deployment. Module 3: Public Key Infrastructure (PKI)

This module explains how to install and configure the Public Key Infrastructure (PKI) requirements necessary to deploy AD FS 2.0. Introducing the Public Key Infrastructure PKI Basics Introduction to Cryptography PKI Design Installing and Configuring Certificate Services Lab : Installing and Configuring a Public Key Infrastructure (PKI) Installing and Configuring an Enterprise Root CA in the A. Datum Active Directory Configure an SSL Certificate for the Web Server Import Certificates in the Necessary Locations Describe the concepts of a Public Key Infrastructure (PKI). Define and discuss the basics of PKI. Describe symmetric key and public key cryptography. Discuss options for PKI design. Describe the steps needed to install and configure Certificate Services. Module 4: AD FS 2.0 Components This module explains how to install and configure the Windows Identity Foundation (WIF), and how to install the AD FS 2.0 service in the federation server role. The Federation Server Role Claims Types, Endpoints, and Attribute Stores AD FS Security The Federation Server Proxy Role Administering AD FS Windows Identity Foundation Lab : Installing AD FS Server Installing AD FS on ADATUM-DC1 Installing AD FS on CONTOSO-DC1 Describe the role of the federation server in an AD FS 2.0 installation. Understand the importance of claims, claim types, endpoints, and attribute stores for a successful AD FS implementation. Discuss best practices for securing an AD FS implementation, including the role of Public Key Infrastructure (PKI) certificates in securing the authentication and communication process. Describe the role of the Federation Server Proxy. Describe the methods available to administer an AD FS server. Understand the role of the Windows Identity Foundation (WIF) in creating claims-based applications. Module 5: Claims-based Authentication in a Single Organization This module explains how to design and deploy AD FS 2.0 to provide claims-based authentication within a single organization. Preparing for AD FS in a Single Organization AD FS Within a Single Organization Understanding Claims and Claim Types Claim Rules and Claim Rule Templates

Creating Claim Rules from Templates Configuring AD FS in a Single Organization Lab : Configuring Claims-based Authentication in a Single Organization Prepare CONTOSO-DC1 with Certificates and Claim Rules Configure the Sample WIF SDK Application Using FedUtil.exe Configure a Relying Party Trust to the WIF SDK Sample Application Configuring Claims-aware Access to SharePoint 2010 Define the certificate requirements for AD FS in a single organization. Discuss PKI certificate management for AD FS. Module 6: Claims-based Authentication in a Business-to-Business Federation This module explains how to design and deploy AD FS 2.0 to provide claims-based authentication in a business-to-business federation scenario. Deploying AD FS in a Federated Environment Configuring a Claims Provider Trust Understanding Home Realm Discovery Managing Claims Across Organizations Lab : Configuring Claims-based Authentication in a Business-to-Business Federation Configure the WIF Sample Application for B2B Federated WebSSO Configure SharePoint 2010 for Federated WebSSO Access Deploy AD FS 2.0 in a business-to-business federation. Configure an AD FS Claims Provider Trust. Describe and configure the Home Realm Discovery process. Manage AD FS Claims and Federation Trust relationships across organizations. Module 7: Advanced AD FS Deployment Scenarios This module explains how to deploy an AD FS server as a federation server proxy. It also explains how to design an AD FS deployment to create a high-availability configuration, and how to configure AD FS 2.0 to achieve interoperability with SAML 2.0- compatible products and applications. Implementing the Federation Server Proxy Planning for High Availability Additional AD FS Configuration Scenarios AD FS 2.0 and SAML Interoperability Lab : Advanced AD FS Deployment Scenarios Install and Configure the AD FS Proxy Install and Configure an AD LDS Attribute Store Configure the AD FS 2.0 server in the Federation Server Proxy role. Configure AD FS 2.0 for redundancy and high availability. Deploy AD FS 2.0 to provide interoperability with SAML 2.0-compliant federation partners.

Module 8: The AD FS Claims Rule Language This module explains how to configure custom AD FS claim rules using the AD FS 2.0 claim rule language. Reviewing the Claims Pipeline and Claims Engine Introducing the Claims Rule Language Lab : The AD FS Claims Rule Language Create Rules Using the Claim Rule Language Query an AD FS Attribute Store Describe the AD FS 2.0 Claims Pipeline and Claims Engine processes. Create and configure custom claim rules using the AD FS 2.0 claim rule language. Module 9: AD FS Troubleshooting This module explains how to audit, troubleshoot, and trace AD FS 2.0 components and claims-aware applications, at both the server and client level. Configuring Auditing for AD FS AD FS Troubleshooting Tracing AD FS Traffic Lab : AD FS Troubleshooting View AD FS Troubleshooting Information View AD FS Web Browser Traffic Configure troubleshooting and security auditing for AD FS 2.0. Use built-in Windows tools to troubleshoot AD FS components and prerequisites. Trace AD FS Web traffic for troubleshooting and configuration purposes. Contact us today. Visit www.quickstart.com or call 800-326-1044