When to Enable Windows Trusts

Applies To: Windows Server 2008

Active Directory Federation Services (AD FS) has built-in support for federation in organizations where a forest trust or external trust exists between two forests that represent the same organization. External trusts and forest trusts are also known as Windows trusts.

Note

External trusts and forest trusts are not required for AD FS to function.

When Windows trusts have been established and you have decided to deploy a Federated Web Single-Sign-On (SSO) with Forest Trust design in your organization, you can configure AD FS to work over Windows trusts.

To successfully implement the Federation Web SSO with Forest Trust design and configure AD FS to support the Windows trust model, do all of the following:

  • Verify that a forest trust exists between two Windows Server 2003 or Windows Server 2008 forests or that an external trust exists between Windows Server 2008, Windows Server 2003, or Windows 2000 Server domains in each forest (where the resource forest trusts the account forest). For more information about Windows trusts, see Administering Domain and Forest Trusts (http://go.microsoft.com/fwlink/?LinkId=63917).

  • Configure the resource Federation Service to enable the Use Windows trusts relationship option in the properties of the account partner. For more information, see Configure an Account Partner to Use Windows Trust.

  • Configure the account Federation Service to enable the Use Windows trust relationship for this partner option in the properties of the resource partner. For more information, see Configure a Resource Partner to Use Windows Trust.

Note

Both the resource Federation Service administrator and the account Federation Service administrator must enable the Windows trust option so that the Federated Web SSO with Forest Trust design can function correctly.