新增至聯盟伺服器陣列聯盟伺服器Add a Federation Server to a Federation Server Farm

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

您安裝同盟服務的角色,並在電腦上設定所需的憑證之後,您就可以設定電腦成為聯盟伺服器。After you install the Federation Service role service and configure the required certificates on a computer, you are ready to configure the computer to become a federation server. 若要將電腦加入新的聯盟伺服器陣列,您可以使用下列程序。You can use the following procedure to join a computer to a new federation server farm.

您可以將電腦加入發電廠使用 AD FS 聯盟伺服器設定精靈。You join a computer to a farm with the AD FS Federation Server Configuration Wizard. 當您將電腦加入現有發電廠使用這個精靈時,僅限 read\ 複本 AD FS 設定資料庫設定電腦,以及它必須從主要聯盟伺服器接收更新。When you use this wizard to join a computer to an existing farm, the computer is configured with a read-only copy of the AD FS configuration database and it must receive updates from a primary federation server.

注意

聯盟網路 Single-Sign-On (SSO) 設計,您必須至少一個聯盟伺服器 account 合作夥伴組織和資源合作夥伴組織中的至少一個聯盟伺服器。For the Federated Web Single-Sign-On (SSO) design, you must have at least one federation server in the account partner organization and at least one federation server in the resource partner organization. 如需詳細資訊,請查看放置聯盟伺服器For more information, see Where to Place a Federation Server.

資格在系統管理員,或相當於、在本機電腦上的最低需求完成此程序。Membership in Administrators, or equivalent, on the local computer is the minimum required to complete this procedure. 檢視詳細資料使用適當的帳號,並群組成員資格,本機和網域預設群組\ (go.microsoft.com\ fwlink\ 方式 http://// # / 嗎?LinkId\ = 83477)。Review details about using the appropriate accounts and group memberships at Local and Domain Default Groups (http://go.microsoft.com/fwlink/?LinkId=83477).

聯盟伺服器新增至聯盟伺服器陣列To add a federation server to a federation server farm

  1. 有兩種方法可以開始 AD FS 聯盟伺服器設定精靈。There are two ways to start the AD FS Federation Server Configuration Wizard. 若要開始精靈中,執行下列其中一個動作:To start the wizard, do one of the following:

    • 同盟服務角色服務安裝完成後,開放 AD FS 管理 snap\ 中,按一下AD FS 聯盟伺服器設定精靈上的連結概觀頁面或控制項窗格。After the Federation Service role service installation is complete, open the AD FS Management snap-in and click the AD FS Federation Server Configuration Wizard link on the Overview page or in the Actions pane.

    • 依照本身需求加以安裝精靈完成,開放 Windows 檔案總管] 之後,瀏覽至C:\Windows\ADFS資料夾,然後 double\ 按FsConfigWizard.exeAnytime after the setup wizard is complete, open Windows Explorer, navigate to the C:\Windows\ADFS folder, and double-click FsConfigWizard.exe.

  2. 歡迎頁面上,確認聯盟伺服器加入現有的同盟服務已選取,然後按一下 [下一步On the Welcome page, verify that Add a federation server to an existing Federation Service is selected, and then click Next.

  3. 如果您已經選取 AD FS 資料庫存在,現有 AD FS 設定資料庫偵測到頁面隨即顯示。If the AD FS database that you selected already exists, the Existing AD FS Configuration Database Detected page appears. 發生這種情形,如果按一下Delete 資料庫,然後按一下 [If that occurs, click Delete database, and then click Next.

    警告

    只有當您確定此 AD FS 資料庫中的資料並不重要或不使用正式作業聯盟伺服器陣列中,選取此選項。Select this option only when you are sure that the data in this AD FS database is not important or that it is not used in a production federation server farm.

  4. 指定主要聯盟伺服器與服務 Account頁面上,在主要聯盟伺服器名稱農場,輸入主要聯盟伺服器的電腦名稱,然後按一下 [瀏覽]On the Specify the Primary Federation Server and Service Account page, under Primary federation server name, type the computer name of the primary federation server in the farm, and then click Browse. 瀏覽]對話方塊中,找出所使用的服務帳號為所有其他聯盟伺服器現有聯盟伺服器,核對,然後按一下 [ [確定]In the Browse dialog box, locate the domain account that is used as the service account by all other federation servers in the existing federation server farm, and then click OK. 輸入密碼並確認,然後按一下下一步:Type the password and confirm it, and then click Next:

    注意

    用於指定聯盟伺服器陣列服務負責的相關詳細資訊,請查看手動設定聯盟伺服器陣列服務 AccountFor more information about specifying a service account for a federation server farm, see Manually Configure a Service Account for a Federation Server Farm. 聯盟伺服器陣列中的每個聯盟伺服器必須指定相同服務負責發電廠才能正常運作。Each federation server in the federation server farm must specify the same service account for the farm to be operational. 例如,如果建立服務 account contoso\ADFS2SVC,聯盟伺服器角色您設定,並將參與相同發電廠每一部電腦必須 contoso\ADFS2SVC 此步驟,精靈中指定聯盟伺服器設定陣列才能正常運作。For example, if the service account that was created was contoso\ADFS2SVC, each computer you configure for the federation server role and that will participate in the same farm must specify contoso\ADFS2SVC at this step in the Federation Server Configuration Wizard for the farm to be operational.

  5. 適用於設定準備頁面上,檢視詳細資料。On the Ready to Apply Settings page, review the details. 若出現正確設定,請按一下下一步來設定 AD FS 使用這些設定。If the settings appear to be correct, click Next to begin configuring AD FS with these settings.

  6. 設定結果頁面上,檢視結果。On the Configuration Results page, review the results. 所有的設定步驟完成時,按關閉以結束精靈。When all the configuration steps are finished, click Close to exit the wizard.

其他參考資料Additional references

檢查清單︰ 設定聯盟伺服器Checklist: Setting Up a Federation Server