TechNet
Products
IT Resources
Downloads
Training
Support
Products
Windows
Windows Server
System Center
Microsoft Edge
Office
Office 365
Exchange Server
SQL Server
SharePoint Products
Skype for Business
See all products »
Resources
Channel 9 Video
Evaluation Center
Learning Resources
Microsoft Tech Companion App
Microsoft Technical Communities
Microsoft Virtual Academy
Script Center
Server and Tools Blogs
TechNet Blogs
TechNet Flash Newsletter
TechNet Gallery
TechNet Library
TechNet Magazine
TechNet Wiki
Windows Sysinternals
Virtual Labs
Solutions
Networking
Cloud and Datacenter
Security
Virtualization
Updates
Service Packs
Security Bulletins
Windows Update
Trials
Windows Server 2016
System Center 2016
Windows 10 Enterprise
SQL Server 2016
See all trials »
Related Sites
Microsoft Download Center
Microsoft Evaluation Center
Drivers
Windows Sysinternals
TechNet Gallery
Training
Expert-led, virtual classes
Training Catalog
Class Locator
Microsoft Virtual Academy
Free Windows Server 2012 courses
Free Windows 8 courses
SQL Server training
Microsoft Official Courses On-Demand
Certifications
Certification overview
Special offers
MCSE Cloud Platform and Infrastructure
MCSE: Mobility
MCSE: Data Management and Analytics
MCSE Productivity
Other resources
Microsoft Events
Exam Replay
Born To Learn blog
Find technical communities in your area
Azure training
Official Practice Tests
Support options
For business
For developers
For IT professionals
For technical support
Support offerings
More support
Microsoft Premier Online
TechNet Forums
MSDN Forums
Security Bulletins & Advisories
Not an IT pro?
Microsoft Customer Support
Microsoft Community Forums
Sign in
Home
Library
Wiki
Learn
Gallery
Downloads
Support
Forums
Blogs
Resources For IT Professionals
United States (English)
Россия (Pусский)
中国(简体中文)
Brasil (Português)
Skip to locale bar
Post an article
Translate this page
Powered by
Microsoft® Translator
Wikis - Page Details
First published by
Alik Levin
When:
23 Aug 2011 2:49 PM
Last revision by
Carsten Siemens
(eMicrosoft Partne)
When:
29 Apr 2013 4:53 PM
Revisions:
18
Comments:
1
Options
Subscribe to Article (RSS)
Share this
Can You Improve This Article?
Positively!
Click Sign In to add the tip, solution, correction or comment that will help other users.
Report inappropriate content using
these instructions
.
Wiki
>
TechNet Articles
>
Windows Azure Application With Active Directory - PaaS
Windows Azure Application With Active Directory - PaaS
Article
History
Windows Azure Application With Active Directory - PaaS
Back to
Windows Azure Active Directory Solutions For Developers
Table of Contents
Scenario
Solution Approach
Analysis
How To's
Code Samples
Resources
Scenario
In this scenario you are developing a web application to be deployed to Windows Azure. It should serve corporate users whose identities and credentials are managed in corporate Active Directory (AD). The users should be provided with Single Sign-On (SSO) capability so they could use their corporate credentials to log on to the Windows Azure deployed web application when they are inside the corporate walls and when outside.
Web Application to be deployed to Windows Azure.
Corporate end users whose identities are managed in corporate AD.
Need to provide SSO so that the end users could use same credentials managed in corporate AD when accessing the Windows Azure deployed web application.
Solution Approach
ACS and AD FS used to solve this scenario. ACS provides federation capability so it can integrate with WS-Federation compliant identity provider such as AD FS. AD FS provides Security Token Service using Active Directory as identity provider.
ACS used to provide federation with AD FS that uses corporate AD as identity provider.
AD FS issues tokens upon successful authentication.
Application uses WIF to manage trust and validate and parse incoming tokens issued by AD FS and transformed by ACS.
When accessing the web application from corporate walls the end user's request tot he application goes through series of redirects without requiring the user to provide his credentials. When accessing the application from outside of the corporate walls the user is required to provide his corporate credentials first through web form provided by AD FS.
Analysis
There is a possibility to configure SSO for Windows Azure deployed web application without use of ACS but directly to AD FS. This is outlined in details in
Single Sign-On from Active Directory to a Windows Azure Application Whitepaper
.
How To's
Single Sign-On from Active Directory to a Windows Azure Application Whitepaper
[not using ACS]
How To: Configure AD FS 2.0 as an Identity Provider
[using ACS]
Code Samples
ACS Code Samples Index
Resources
Deploying ACS Federated Applications and Service To Windows Azure
Securing Windows Azure Web Role ASP.NET Web Application Using Access Control Service v2.0
Identity and the Windows Azure Platform
ACS
,
AD FS
,
adfs
,
cloud
,
en-US
,
has image
,
Identity
,
WIF
[Edit tags]
Leave a Comment
Please add 5 and 7 and type the answer here:
Post
Wiki - Revision Comment List(Revision Comment)
Sort by:
Published Date
|
Most Recent
|
Most Useful
Comments
Carsten Siemens
29 Apr 2013 4:53 PM
Carsten Siemens edited Revision 16. Comment: fixed typo
Edit
Page 1 of 1 (1 items)
Wikis - Comment List
Sort by:
Published Date
|
Most Recent
|
Most Useful
Posting comments is temporarily disabled until 10:00am PST on Saturday, December 14th. Thank you for your patience.
Comments
Posted by
Carsten Siemens
on
29 Apr 2013 4:53 PM
Carsten Siemens edited Revision 16. Comment: fixed typo
Edit
Page 1 of 1 (1 items)