Hey all. Today, I will show how to configure the claims provider trust between two AD FS farms to allow system admins give access to applications federated to an AD FS farm with users coming from another farm.
Category: Microsoft AD FS
AD FS – Identifying servers running the Web Application Proxy service in the AD FS environment
Hello everyone. In today’s article I’ll quickly explain how to identify which WAP (Web Application Proxy) servers are configured in the AD FS farm using the Certificate Store and also PowerShell.
AD FS – Updating the SSL and Service Communication Certificates on AD FS
In today’s article, I’ll explain how to generate and update the SSL certificate on AD FS using Microsoft Entra Connect and update the service communication certificate using the AD FS console.
AD FS – Updating the Token-signing and Token-decrypting certificates in AD FS
Update notice — September 2026: This article contains commands from the Azure AD or MSOnline PowerShell modules maintained since its original publication. Microsoft has deprecated these modules and recommends Microsoft Graph PowerShell…
AD FS – Protecting users with AD FS Extranet Smart Lockout
Hello everyone. In today’s article I’ll cover a very interesting AD FS feature that helps protect domain accounts from attacks such as “password spray” using AD FS Extranet lockout. This feature is called AD FS Extranet Smart Lockout.
AD FS – How to Configure JEA (Just Enough Administration) with AD FS
Hello everyone. In today’s article, I’ll explain how to configure JEA (Just Enough Administration) in the AD FS service. This feature allows AD FS service administrators to delegate limited access to other users without the need to grant administrative access to the servers. One example is delegating to user support technicians permission to unlock accounts locked by AD FS Smart lockout.
Microsoft Entra ID – How to limit access to Outlook Web Access data using a CA policy
Hello everyone. Today I’ll present a step-by-step guide on how to integrate Conditional Access policies with Exchange Online policies to limit access to OWA. With the rise of mobility and the growing concern organizations have about protecting information stored on mobile devices, administrators face the difficult task of protecting the information that users can access.
AD FS – Monitoring AD FS with the Microsoft Entra Connect Health Agent for AD FS
Hello everyone. In today’s article we’ll show you how to install the Microsoft Entra Connect Health Agent for AD FS and monitor the environment through the Azure portal.
AD FS – Controlling Access to the Azure Portal Using AD FS Access Policies
Hello everyone. In today’s article, we’ll demonstrate how to restrict access to Azure AD resources using AD FS access control rules for domains federated with Azure AD. With AD FS access control rules, you can control internal and external access to an RPT (relying party trust) using location, device status, or even access containing a specific attribute.
AD FS – Integrating Microsoft Entra Multifactor Authentication with AD FS
Hello, everyone. In today’s article, we’ll show how to integrate Microsoft Entra multifactor authentication with AD FS to allow users to use passcodes generated by Microsoft Authenticator when accessing an application.
