question

HallJrRodney-7270 avatar image
HallJrRodney-7270 asked ·

Pass windows credentials through ADFS for external site without being prompted??

im running into an issue with passing logged in user credentials through internal ADFS to external website without being prompted for credentials. I added the site into the trusted sites, set the "automatic logon with current username and pass", made sure the settings in "advanced" was correct. but no matter what i change, im still being promoted with the ADFS login page.

any ideas??

adfs
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

piaudonn avatar image
piaudonn answered ·

ADFS does not pass credentials.

In order to achieved Sigle Sign On for an internal application you will need:

  1. Configure the application to use Federation and to point/redirect ADFS for authentication.

  2. Configure a Replying Party Trust for the application in ADFS.

  3. Confirm that Windows Integrated Authentication is configured on the primary authentication policy.

  4. Confirm that the ServicePrincipalName of the farm is set on the service account and only on the service account.

  5. Make sure the client is domain joined and have the URL of the ADFS server (not the application) in either the Trusted Site List or the Intranet Site List.

  6. Make sure the useragentstring of the browser is listed in the list of supported UAS for Windows Integrated Authentication (example for Chrome available here: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-intranet-forms-based-authentication-for-devices-that-do-not-support-wia#configuring-wia-for-chrome).


2 comments Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

this is for a "cloud" hosted service, so it is an external site/application

0 Votes 0 · ·
piaudonn avatar image piaudonn HallJrRodney-7270 ·

That's irrelevant in federation. Still need to check all these steps.

0 Votes 0 · ·