Copyright 2015 http://itfreetraining.com



Similar documents
LAB 1: Installing Active Directory Federation Services

Renew ADFS and ADFS Proxy servers SSL Service Communication certificate

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

Wavecrest Certificate

IIS, FTP Server and Windows

APNS Certificate generating and installation

IceWarp Notifier User Guide

Virtual Office Remote Installation Guide

ADFS Integration Guidelines

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Browser-based Support Console

ILTA HAND 6B. Upgrading and Deploying. Windows Server In the Legal Environment

etoken Enterprise For: SSL SSL with etoken

How To Set Up Dataprotect

HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents

Enable SSL for Apollo 2015

Remote Monitoring Service - Setup Guide for InfraStruXure Central and StruxureWare 1 5

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

CLEARONE DOCUMENT (REVISION 1.0) October, with Converge Pro Units

Use 802.1x EAP-TLS or PEAP-MS-CHAP v2 with Microsoft Windows Server 2003 to Make a Secure Network

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

Versions Addressed: Microsoft Office Outlook 2010/2013. Document Updated: Copyright 2014 Smarsh, Inc. All right reserved

Active Directory Integration for Greentree

Acunetix Web Vulnerability Scanner. Getting Started. By Acunetix Ltd.

Setting Up SSL on IIS6 for MEGA Advisor

Configuring Thunderbird for Flinders Mail at home.

Using Internet or Windows Explorer to Upload Your Site

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

CA Nimsoft Service Desk

Direct Storage Access Using NetApp SnapDrive. Installation & Administration Guide

eadvantage Certificate Enrollment Procedures

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Setup Guide for AD FS 3.0 on the Apprenda Platform

Internet Explorer 7 for Windows XP: Obtaining MIT Certificates

4cast Client Specification and Installation

Professional Mailbox Software Setup Guide

Check current version of Remote Desktop Connection for Mac.. Page 2. Remove Old Version Remote Desktop Connection..Page 8

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

PRODUCT WHITE PAPER LABEL ARCHIVE. Adding and Configuring Active Directory Users in LABEL ARCHIVE

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

Using TLS Encryption with Microsoft Outlook 2007

Aspera Connect User Guide

Training module 2 Installing VMware View

How to use mobilecho with Microsoft Forefront Threat Management Gateway (TMG)

How to use SURA in three simple steps:

Richmond Systems. SupportDesk Quick Start Guide

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

TSM for Windows Installation Instructions: Download the latest TSM Client Using the following link:

How to Configure a Secure Connection to Microsoft SQL Server

Chapter. Managing Group Policy MICROSOFT EXAM OBJECTIVES COVERED IN THIS CHAPTER:

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Microsoft Exchange 2010 and 2007

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Mozilla Thunderbird: Setup & Configuration Learning Guide

Central Administration QuickStart Guide

SQL Server 2008 and SSL Secure Connection

Microsoft IIS 4 Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Trauma/Recon Sales. Step by step guide to using the Smith & Nephew User Gateway (SNUG) Global Remote Access

Configuring on Mobile Devices

RMS Cloud - Setup Instructions for Windows Computers

HarePoint Password Change Manual

Certificate Management for your ICE Server

Exchange 2010 PKI Configuration Guide

NSi Mobile Installation Guide. Version 6.2

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

enter the administrator user name and password for that domain.

IMAP and SMTP Setup in Clients

Symantec Endpoint Encryption Full Disk

LDAP Server Configuration Example

Connecting to LRDC Fileserver Remotely Using Windows XP & SRemote VPN

Install the Production Treasury Root Certificate (Vista / Win 7)

Configure Single Sign on Between Domino and WPS

User guide. Business

Microsoft Lync TM Order & Provisioning. Admin Guide

Sophos Anti-Virus for NetApp Storage Systems startup guide

Outlook 2010 Setup Guide (POP3)

Using the Remote Desktop Portal

Lab 05: Deploying Microsoft Office Web Apps Server

SSL Intercept Mode. Certificate Installation Guide. Revision Warning and Disclaimer

Microsoft IAS Configuration for RADIUS Authorization

Hosted Microsoft Exchange Client Setup & Guide Book

How to share media files through Windows Media Player 11

Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

Configuring Active Directory with AD FS and SAML for Brainloop Secure Dataroom Setup Guide

3. On the Accounts wizard window, select Add a new account, and then click Next.

Document Classification: Public Document Name: SAPO Trust Centre - Generating a SSL CSR for IIS with SAN Document Reference:

Set Up Setup with Microsoft Outlook 2007 using POP3

Step-by-Step Guide for Setting Up VPN-based Remote Access in a

VERITAS Backup Exec 9.1 for Windows Servers Quick Installation Guide

Team Foundation Server 2013 Installation Guide

Client configuration and migration Guide Setting up Thunderbird 3.1

How to setup a VPN on Windows XP in Safari.

Setting Up the Device and Domain Administration

Transcription:

This video will install Active Directory Federation Services on Windows Server 2012. In a previous video, an enterprise CA was installed and configured. This video will use that enterprise CA to issue a certificate for this install of Active Directory Federation Services.

Demonstration Installing ADFS Role To start the install, select Server Manager from the quick launch bar and then from Server Manager select the option on the home screen Add roles and features. From the Add Roles and Features wizard, the install will be performed on the local server so the default options can be used for the first few screens. On the Select server roles screen, tick the option Active Directory Federation Services and press next. Server Manager may prompt you to install additional features. If this window appears, press the button add features. On the Select Features screen, no additional features are required so it safe to press next and move on. The next few screens of the wizard relate to the install of Active Directory Federation Services. Once past the welcome screen for Active Directory Federation Services screen, the next screen asks for a decision on which components need to be installed. In this case the component Federation Service needs to be ticked. The other components are not required for a base install of Active Directory Federation Services. The next screen relates to the install of IIS since this is required by Active Directory Federation Services. The default options work fine so the wizard can be completed and the Active Directory Federation Services role has been installed and ready to be configured.

Demonstration Configuring Active Directory Federation Services To configure Active Directory Federation Services, from Server Manager, select the exclamation mark under the flag icon at the top right of the screen and then select the option Run the AD FS Management snap-in. This will open the AD FS Management tool, however no option will be able to be configured until AD FS has been configured. To finish the configuration select the option AD FS Federation Server Configuration Wizard. The first screen of the wizard will ask if you want to create a new Federation Service. If you have a Federation Service on the network already, this install can be added to that one to form a farm. In this case, no existing Federation Service exists on the network so the option Create a new Federation Service will be used. The next screen will ask if a new federation server farm is to be created or a standalone federation server. Both options give the same functionality, however if you select the stand-alone option you will not be able to add additional servers to form a farm later on. If you are not sure, you should select the option New federation server farm as this gives you that option later on. You are not able to change your mind after the install. The next screen will ask for a certificate. If you do not have a certificate showing, you can follow the procedure for creating an Enterprise CA below or in a later video the procedure for creating a certificate using a standalone CA. If a certificate has been created and is not showing, it most likely has been created using the wrong settings. The next screen will ask for the service account that will be used with Active Directory Federation Services. If you do not have a service account already created, you can use the procedure below to create a service account. Enter in the name of the service account and password. The service account will require administrator rights to the local server. To do this, open the tools menu and select the option Computer Management. From computer management, expand down to Local Users and Groups and then open Groups. With the groups container open, right click on the administrators groups and select the option Add to Group. To add the service account, press the add button and then enter in the name of the service account that you are using with Active Directory Federation Services. Exit Computer Management and go back to the Federation Service configuration wizard. The wizard can now be completed and Active Directory Federation Services will be configured. On the finial screen of the wizard, you may receive a warning message for the server settings. If the warning says that the SPN for the user account has already been set, this means the configuration attempted to configure this setting but was not able to.

Demonstration creating a certificate for Federation Services To create a certificate using an enterprise CA on the network, move the mouse to the top left or right of the screen to open charms. Select the search option and then enter in MMC. MMC is required because there is no shortcut in the start menu. From MMC, select the file option and then select the option Add/Remove Snap-in and then from the list select the option Certificates and press add. When the certificate MMC is added, Windows will ask which certificates are to be managed. In this case the option Computer account was selected as the certificate required for Federation Services needs to be stored on the local computer. The next screen will ask which computer you want to manage certificates on. In this case certificates will be managed on the local computer so the option Local computer (This computer this console is running on) will be selected. Once the MMC for certificates is open, the next step is to request a certificate from the Enterprise CA for use with this server. To do this the view needs to be changed to purpose view from the default view of logical. To change the view, expand the certificates snap-in and then right click on the container, for example the personal container, and select options found under view. Once the view has changed to logical view, right click the container Server Authentication and then select the option Request New Certificate found under the menu All Tasks. This will start the enrollment certificate wizard. Once past the welcome screen leave it on the option Active Directory Enrollment Policy and move on. The certificate template that will be used was created in a previous video. If you have not done that already you will need to do this before requesting a certificate. The next screen will show the certificate templates that can be requested by auto enrollment. In this case ADFS SSL Certificate 2012 was chosen as this was created in an early video. Once the certificate has been selected, press the button enroll. Once the wizard has been completed, the certificate will be requested from the Enterprise CA and stored in the local computer store. It will automatically be updated using auto enrollment as required. Demonstration creating a service account Go to a computer that has Active Directory User and Accounts available. This can be a Domain Controller or a client computer like Windows 8.1 with RSAT installed. Open Server Manager from the quick launch bar. From Server Manager, select the pull down menu tools and select the option Active Directory Users and Computers. From Active Directory Users and Computers, expand down to the Users container, right click the users container and select User under the New Menu. In this case the first name was ADFS and service was used for the last name. The login name was ADFSService2012. You are free to choose any name that you want.

On the next screen a password was entered and the only tick box ticked is Password never expires. If the password were to expire, then the Active Directory Federation Service would stop running. Generally on systems like these the administrator will need to remember to manually change the password. The wizard can now be completed to create the service account. See http://youtube.com/itfreetraining or http://itfreetraining.com for our always free training videos. This is only one video from the many free courses available on YouTube. References None