ADFS, UPN, and public DNS namespaces


  1. for adfs, if have multiple upn namespaces same root namespace, of dns namespaces match upn namespaces need publicly available in dns?   or root namespace?
  2. do need own root namespace?
  3. can 2 different organizations utilize separate adfs , utilize same root namespace?

we want our users able log cloud services upns match email addresses, can remember logon id.
have 5 e-mail domains (and lot of users)
although share same root, not own root namespace, affiliate does.

there namespace own root of potentially use, root domain publicly available, child domains behind firewalls.  bit less desireable, because users need remember additional information.

want have set 1 highly available adfs/adfs proxy farm.

example:
root.com (the domain not own, have affiliate does)
agency1.root.com (email domain 1)
agency2.root.com (email domain 2)
agency3.root.com (email domain 3)
agency4.root.com (email domain 4)
agency5.root.com (email domain 5)
ourforest.root.com (publicly exposed dns namespace)
agency1.ourforest.root.com (firewalled dns namespace)
agency2.ourforest.root.com (firewalled dns namespace)
agency3.ourforest.root.com (firewalled dns namespace)
agency4.ourforest.root.com (firewalled dns namespace)
agency5.ourforest.root.com (firewalled dns namespace)

4. our best option utilizing adfs?

 

 

hello,

as ad fs main part in question please use following forum: http://social.msdn.microsoft.com/forums/en-us/geneva/threads/


best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.


Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Group Policy Event ID 1058 Error Code 1326 (The user name or password is incorrect)

Suspicious event log Event ID: 4905

DCOM received error "2147746132" from...