Checklist: Implementing a Federated Web SSO Design

Applies To: Windows Server 2003 R2

This parent checklist includes cross-reference links to important concepts about the Federated Web Single-Sign-On (SSO) design. It also contains links to subordinate checklists that will help you complete the tasks that are required to implement this design.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a conceptual topic or to a subordinate checklist, return to this topic after you review the conceptual topic or you complete the tasks in the subordinate checklist so that you can proceed with the remaining tasks in this checklist.

ChecklistChecklist: Implementing a Federated Web SSO Design

  Task Reference
Checkbox

Review important concepts and examples for the Federated Web SSO design and determine which Active Directory Federation Services (ADFS) deployment goals you can use to customize this design to meet the needs of your organization.

Conceptual topicFederated Web SSO design

Conceptual topicFederated Web SSO example

Conceptual topicIdentifying Your ADFS Deployment Goals

Checkbox

Review the hardware, software, certificate, Domain Name System (DNS), account store, and client requirements for deploying ADFS in both partner organizations.

Conceptual topicAppendix A: Reviewing ADFS Requirements

Checkbox

According to your design plan, install one or more federation servers in each partner organization.

noteNote
For the Federated Web SSO design, you need at least one federation server in the account partner organization and at least one federation server in the resource partner organization.

Checklist topicChecklist: Installing a federation server

Checkbox

(Optional) Determine whether or not your organization needs a federation server proxy. If your design plan calls for a proxy, you can install one or more federation server proxies in each partner organization.

Checklist topicChecklist: Installing a federation server proxy

Checkbox

If you are an administrator in the resource partner organization, install one or more ADFS-enabled Web servers to host your preferred federated application using the appropriate ADFS Web Agent.

Note

The account partner administrator does not have to complete the following checklist.

Checklist topicChecklist: Installing an ADFS-enabled Web server

Checkbox

According to your design plan, share certificates, configure clients, and configure the Federation Service in both partner organizations so that they can communicate over a federation trust.

Checklist topicChecklist: Configuring the account partner organization

Checklist topicChecklist: Configuring the resource partner organization

Checkbox

If you are an administrator in the resource partner organization, install either a claims-aware application or a Windows NT token-based application, or both, using the appropriate checklist.

Note

The account partner administrator does not have to complete either of the following checklists.

Checklist topicChecklist: Installing a claims-aware application

Checklist topicChecklist: Installing a Windows NT token-based application