Section 3 - Chapter 17 Flashcards

1
Q

AD FS - Federation Service

A

Created by servers that share a trust policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

AD FS - Federation Service Proxy

A

Server sits in perimeter, passes info from user’s browser to the federation service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

AD FS - 3 Architectural Designs

A

Federated Web SSO - links apps contained within an extranet in resource orgs to internal directory store of accounts org

Web SSO - used when users do not have AD DS accounts

Federation with Cloud Services - access to cloud-based services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

AD FS - Account Federation Server

A

Server that is hosted in the account orgs internal network

Performs claims mapping and issues tokens

Authenticates user

Extracts federation attributes and group membership for attribute store

Creates claim

Generates and signs security token

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AD FS - Configuration db

A

db stores config data for AD FS instance or Federation Service

SQL (all read/write), 2005 or later, fsconfig.exe to create, located centrally, no need to place on federation server, auto discard token replays when detected
or
WID (first primary read/write, all others read), AD FS Fed Server Config Wiz, stand alone or farm deployment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AD FS - Identity Metasystem Interoperability Protocol (IMIP)

A

Outlines how to provision Information Cards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

AD FS - Information Cards

A

Digital Identities

Managed - issued by claims providers

Personal - issued by users themselves

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AD FS - Information Card Group Policies

A

Two GPOs that outline how to provision and how to use Information Cards in AD DS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

AD FS - Security Assertion Markup Language (SAML)

A

Web SSO protocol that outlines http web browser redirects to exchange assertion data used to authenticate and authorize clients across firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

AD FS - SAML Security Token

A

Special data format used to exchange claims between claims providers and relying parties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

AD FS WS-Federation

A

Web server specification outlines standards to be used when implementing federation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

AD FS Components

A

Attribute Store - db or directory, stores user accounts and attributes

AD FS Config db - scope of a single instance

Claims

Claim Rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

AD FS Claims Value and Sources

A

AD FS supports access to apps thru generation of claims

Value sourced thru attribute store or transformed into another by applying a rule

Supported: UPN, email, common name, group membership, private personal identifiers, SAML name identifiers, user account or group account SIDs, Windows account names

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

AD FS - Claim Rules

A

Business logic that takes incoming claims, applies conditions and generates outgoing claims

Processed thru claims engine

Support permission or dential of access to resources within the Federation Service

Processing: passed thru as is, filtered to specific condition, transformed to new claim

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

AD FS - Claims Templates

A

Pass thru or filter incoming claim

Transform incoming claim

Send LDAP attributes as claim

Send group membership as claim

Send claims using custom rules

Permit or deny users based on incoming claims

Permit all users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

AD FS - Federation Server Certs

A

Server Authentication Cert - secures web traffic between federation server and Federation Service Proxy or web clients, bound to Default Web Site, aka Server Communication Cert

Token Signing Cert - ensures that security token cannot be tampered with during transit

AD FS issues a self signed cert at install, replace with a trusted root

Verification Cert - public key of token signing cert

17
Q

AD FS - Federation Service Proxies Certs

A

Server Authentication Cert to support SSL encrypted communication with web clients

18
Q

AD FS and AD CS

A

FS can rely on CA for certs

Certs must be trusted cert authorities for outward facing roles

If not trusted, you must modify the Trusted CA store on each web client

19
Q

AD FS 2.0 vs 1.1

A

Built on interoperability standards of OASIS

Can now be integrated with 3rd party attribute stores

AD LDS no longer supported as an attribute store

Windows NT token based web agent no longer supported

Claims aware web agent for SharePoint 2007 no longer supported, use SharePoint 2010

Federated Web SSO with Forest Trust deployment no longer supported

20
Q

AD FS Time Sync

A

Time cannot be off by more than 5 minutes, token time stamps will be invalid, use PDC Emulator Operations Master for clock synch

Use Network Time Protocol (NTP) to linke servers to external clock

21
Q

AD FS Config

A

Import server authentication cert to default web servers

Config federation servers and federation server proxies (FSPs) in each AD DS domain

Config token-signing and token-decrypting certs on federation servers

Verify operational

22
Q

AD FS - PowerShell

A

AD FS support module-

add-PSSnapin Microsoft.Adfs.Powershell

Federation server proxies can only be managed thru WinPS

23
Q

AD FS - Files Installed

A
Windows PowerShell
.Net Framework 
Web Server (IIS)
Windows Identity Foundation
24
Q

AD FS - Default Web Sites Config

A

Admin Tools, IIS Manager, ServerName, Server Certs, Create Cert

Sites, Default Web Site, bindings

25
Q

AD FS Config Wizard

A

Stop AD FS server
Start WID db service
Generate signing and token encryption certs and set to auto rollover
Select SSL Cert
Assign Network Service Account - gives access to db, cert private keys and end points
Enable default set of end points
Deploy browser sign in web site
Federation Service name Server03.contoso.com
Start AD FS server

26
Q

AD FS Client Computers

A

Enable IE to access and trust the account federation server

GPMC - User Config, Policies, Windows Settings, IE Maintenance, Security

Distribute federation certs to clients

GPMC - Computer Config, Policies\Windows Settings\Secuirty Settings\Public Key Policies

Trusted Root Cert Authorities, Import