Michael Posted September 19, 2019 Posted September 19, 2019 Hi all, Has anyone ever changed an existing/live setup from ADFS + Azure AD Connect to just Azure AD Connect, with SSO enabled? What was involved in the process and any gotchas to be made aware of? Thanks in advance!
mrbios Posted September 27, 2019 Posted September 27, 2019 I did about 2 years ago, looks like it might be easier now than it used to be. I used Option B here https://docs.microsoft.com/en-us/azure/active-directory/hybrid/plan-migrate-adfs-pass-through-authentication 2 years ago, i don't think option A existed then. It was pretty seamless, no one even noticed. 2
rich_tech Posted October 5, 2019 Posted October 5, 2019 Thanks for this, im currently going to be undertaking a similar operation and retiring out our old ADFS 2.0 server finally over the coming weeks.
ajg Posted October 6, 2019 Posted October 6, 2019 Planning to do this over half term too. Just to complicate matters we have a local azure MFA server which we also plan to retire and use the azure cloud option (which I think is the only option now).
CHiLL Posted October 7, 2019 Posted October 7, 2019 This is something that I'd like to move to, but unsure if I have the expertise to pull this off. I certainly don't have the downtime available any more, since the school is shut during Oct/Feb half terms, all Christmas holidays and three of the six weeks holidays. That only leaves the Easter break, May half term and three weeks of summer. But Easter/May are filled with revision sessions, so I can't even afford downtime then. I wonder how long it would take it we were to get a third party contractor in to do it (obviously extra costs involved).
rich_tech Posted October 20, 2019 Posted October 20, 2019 thanks for the guides, yesterday I changed ours from ADFS / Azure AD Connect to PHS / Azure AD Connect, I did plan to go to PTA as it was "Slightly Less Hassle", but on working through the document, I got met with the error "This Authentication is not supported on Servers older than 2012R2" at the AD Connect changes (its Server 2012/ADFS2.0) so I had to swing it on to doing the PHS route, its over now and working fine and was fairly straightforward even with our multi-domain forest. Our end goal was needed because we are bringing onboard a fair few systems now which use OpenID connect and other forms of SSO which we wanted to do, our original ADFS was the solution provided by a MSP who left us no documentation about what had been done and it was a bit creaky with its age anyhow.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now