ADFS Flashcards

1
Q

What does ADFS stand for?

A

Active Directory Federation Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is IDP?

A

Identity Service Provider (EG. DC which has AD on it)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does SP stand for?

A

Service Provider (aka Relying Party)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When you install ADFS, how many certificates do you get?

A

3 Certificates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does the Federation generate and provide to the client when accessing thirdparty app?

A

Token + Claims

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does the Federation generate and provide to the client when accessing the third-party app?

A

Token + Claims (Via SAML or JWT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain the process for end user trying to access relying party/application (eg. O365)?

A
  1. Application (eg O365) checks if there is a TRUST with FS.
  2. FS checks with AD/DC to confirm user identity (if located outside of the network)
  3. FS Provides End-User with a Signed Token + Claims Statement
  4. Token + Claims is given to the application
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What if Federation Service also known as?

A

Claims provider

STS (Secure Token Service)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain the steps for a user to access SSO application if he is located outside of the firewall?

A
  1. External users redirected (via external DNS servers) to the company’s web proxy server
  2. Web Proxy confirms Identity with Proxy-> ADSF-> DC.
  3. DC -> ADFS (Claims+Token)-> WebProxy -> External user
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Web Application Proxy (WAP)?

A

The proxy server is generally located at the DMZ (Perimiter Network), WAP provides external users access to web applications using Active Directory Federation Services (AD FS), and in this capacity the WAP functions as an AD FS proxy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is ADFS?

A

ADFS is a Federated Identity management solution which provides users with single sign-on access to systems and applications located outside of the firewall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How is ADFS used with Azure AD?

A

On-prem ADFS needs to build a trust with Azure AD and then Azure AD manages the FS between AD Azure and (Relying Parties) applications such as SalesForce, Box

How well did you know this?
1
Not at all
2
3
4
5
Perfectly