Jump to content

Recommended Posts

Posted
I am in the process of writing a simple installation checklist and have a query about ADFS, Single Sign-On & AD sync. I was told by a former colleague that you needed ADFS running on a separate server to the one running your AD DirSync tool. Is this true? Can you not have ADFS, SSO & AD Sync all on one box?
Posted
Can you not have ADFS, SSO & AD Sync all on one box?

 

First, ask yourself exactly why you want ADFS at all? :)

 

Combining the roles into one box is, IMO, a bad idea. If you do go down the ADFS route you will need ensure you have a reliable, highly available infrastructure as you'll be putting yourself in the middle of any authentication with Office 365. If your single little box goes offline for any reason, nobody can sign into Office 365.

 

I wrote this up - it's probably in need of a little bit of updating, but the gist is still true: Deploying Office 365 Education? You don't need single sign-on, and here's why!

 

If you're still going to go ahead with ADFS you should look at around 4 boxes: 2 ADFS internal, 2 ADFS proxies in your DMZ. You'll also need to look into load balancing. You can probably cut corners slightly in some areas, but at the very minimum you'll need two: 1 ADFS internal and 1 ADFS proxy in the DMZ.

  • Thanks 2
Posted (edited)

James

 

Really useful advice in your article about implementing Office 365. CSO it will be. If (after a time) for the sake of argument a school has a locally implemented Exchange 2013 instance and wants to move from a CSO to federated SSO hybrid solution ie with Exchange 2013 on premise (and initially mailboxes on premise) I know this is possible and fairly straight forward to do. My question relates to this is:- If a transport rule is applied on the local Exchange instance eg block group of students A from e-mailing group of students B. Would this apply when accessing the mailbox though O365? Or are transport rules applied elsewhere ie do the local transport rules take precedence?

 

OK. Just read a few more articles on this and will probably stick with CSO. But would still be interested in the answer.

Edited by Dave_O
  • 2 weeks later...
Posted
First, ask yourself exactly why you want ADFS at all? :)

 

Combining the roles into one box is, IMO, a bad idea. If you do go down the ADFS route you will need ensure you have a reliable, highly available infrastructure as you'll be putting yourself in the middle of any authentication with Office 365. If your single little box goes offline for any reason, nobody can sign into Office 365.

 

I wrote this up - it's probably in need of a little bit of updating, but the gist is still true: Deploying Office 365 Education? You don't need single sign-on, and here's why!

 

If you're still going to go ahead with ADFS you should look at around 4 boxes: 2 ADFS internal, 2 ADFS proxies in your DMZ. You'll also need to look into load balancing. You can probably cut corners slightly in some areas, but at the very minimum you'll need two: 1 ADFS internal and 1 ADFS proxy in the DMZ.

 

Apologies for the slow response, thank you for the advice. The organisation in question is a primary school with about 200 kids and 35-40 staff (Teachers, TA's & SLT). They also only have 1 server (technically 2 due to the Hyper-V DC) currently in use. The organisation I work for doesn't know a lot about the deployment/implementation of Office365 so we are sort of writing our own document as we go so this would be useful advice for us to put in our document (we only tend to share it internally). Just so I have my understanding right, you advise only having AD Sync and not bothering to do SSO? Currently I have only added their staff users with a CSV file (their original request) but we are at the stage where we need to research AD Sync a bit more and the have agreed to be our guinea pig once more!

Posted
Just so I have my understanding right, you advise only having AD Sync and not bothering to do SSO? Currently I have only added their staff users with a CSV file (their original request) but we are at the stage where we need to research AD Sync a bit more and the have agreed to be our guinea pig once more!

 

No, I'm not saying don't bother with SSO. I wrote the post because I was frustrated with people not fully understanding the capabilities and making wild assumptions about what they'd need.

 

ADFS is great, it's powerful and it's secure. It's just overkill in many cases, technically beyond what many folks in schools are used to managing and doesn't necessarily give the perfect solution most people have in their minds.

 

For a primary school with such a small number of users, I would recommend password sync. The infrastructure required to implement ADFS properly (and I don't believe in doing it any other way, really) is going to be more than is easily justifiable to the school. (By which I mean the cost, time and effort required to implement ADFS vs. password sync are not going to significantly improve pupil outcomes)

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...