Checklist: Implementing a Resource Account Mapping Method

Applies To: Windows Server 2008

This checklist includes the tasks for determining which resource account mapping method to implement. Complete the tasks in this checklist to successfully deploy a Windows NT token–based application. You do not have to complete this checklist if you are deploying a claims-aware application.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a procedure, return to this topic after you complete the steps in that procedure so that you can proceed with the remaining tasks in this checklist.

Checklist: Implementing a resource account mapping method

  Task Reference

Review information in the Active Directory Federation Services Design Guide to determine whether to use one or more of the resource account, resource group, or group-to-UPN (user principal name) mapping methods.

Determine Your Resource Account Mapping Method

Review information in the Active Directory Federation Services Design Guide about when and how to use resource accounts in the resource forest.

When to Use Resource Accounts

Review information in the Active Directory Federation Services Design Guide regarding which setting in the resource Federation Service can best optimize resource account mapping methods.

Select the Optimal Resource Account Option

Review information in the Active Directory Federation Services Design Guide about when and how to use resource groups in the resource forest.

When to Use Resource Groups

Review information in the Active Directory Federation Services Design Guide about whether you should use the group-to-UPN mapping method in the resource forest instead of the resource group mapping method.

When to Use Resource Groups

If you will be using resource accounts for mapping, create and configure the accounts for use with Windows NT token–based applications.

Note
This procedure is necessary only when you use the resource account mapping method.

Create a Resource Account in the Resource Partner Forest

If you will be using resource groups for mapping, associate an existing security group in the resource forest with a specific organization claim in the resource Federation Service.

Note

This procedure is necessary only when you use the resource group mapping method.

Map an Organization Group Claim to a Resource Group