Prerequisites for installing AD FS
Updated: June 21, 2013
Applies To: Windows Server 2012 R2
This topic summarizes AD FS installation permission requirements and other prerequisites, including options to extend the Active Directory schema to create objects and containers that are required to support Device Registration Service (DRS) for Active Directory Workplace Join. For more detailed information about deploying AD FS, see How to deploy AD FS in Windows Server 2012 R2.
This section covers permissions that are required to install Active Directory Federation Services (AD FS).
To install any server role or feature, including the AD FS server role or the Web Application Proxy role service (part of the Remote Access server role), you must be a member of the local Administrators group on the target server.
To configure AD FS, whether you create a new federation server farm or add nodes to an existing federation server farm, you must be a member of the Domain Admins group in the domain to which the federation server is joined.
To configure Web Application Proxy, you must be a member of the local Administrators group on the target server, and you must have the credentials of a local administrator on the AD FS server.
To enable the Device Registration Service (DRS), you need to be a member of the Enterprise Admins group or the Domain Admins group in the root domain of the forest in order to create the DRS configuration and registered device containers and objects in Active Directory.
DRS also requires the Windows Server 2012 R2 Active Directory schema. To extend the schema, you must run adprep /forestprep, which requires Schema Admins, Enterprise Admins, and Domain Admins credentials. For more information about how to run adprep /forestprep, see Running Adprep.exe.
The following table lists hardware and software prerequisites.
Hardware |
Minimum requirement
Recommended configuration:
|
Certificates |
|
Browser |
Any web browser with JavaScript capability can work as an AD FS client. JavaScript must be enabled, and cookies must be enabled for browser-based sign-in and sign-out. Support for Transport Layer Security/Secure Sockets Layer (TLS/SSL) is also required. |
Device Registration Service (DRS) |
To install the DRS, the Active Directory schema must be Windows Server 2012 R2. For more information about how to extend the schema, see Running Adprep.exe. |
To create the new containers and objects, the AD DS schema must be extended to the Windows Server 2012 R2 level. For the permissions that are required to update the AD DS schema, see Installation permission requirements. There are three ways to extend the schema:
In an existing Active Directory forest, run adprep /forestprep from the \Support\Adprep folder of the Windows Server 2012 R2 operating system DVD on any 64-bit server that runs Windows Server 2008 or later. In this case, no additional domain controller has to be installed, and no existing domain controllers have to be upgraded.
To run adprep /forestprep, you must be a member of the Schema Admins group, the Enterprise Admins group, and the Domain Admins group of the domain that hosts the schema master.
In an existing Active Directory forest, install a domain controller that runs Windows Server 2012 R2. In this case, adprep /forestprep runs automatically as part of the domain controller installation.
During the domain controller installation, you must enter additional credentials to run adprep /forestprep.
Create a new Active Directory forest by installing AD DS on a server that runs Windows Server 2012 R2. In this case, adprep /forestprep does not need to be run because the schema will be initially created with all the necessary containers and objects to support DRS.
To create a new forest, you must be a member of the Administrators group on the server where you install AD DS.
For more information about Adprep.exe, see Running Adprep.exe. For a list of objects and containers that are created when the AD DS schema is extended for Windows Server 2012 R2, see the SCH.ldf files that are listed for DRS in Changes to Adprep.