檢查清單︰ 設定資源合作夥伴公司Checklist: Configuring the Resource Partner Organization

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

資源合作夥伴組織包含裝載 Web\ 為基礎的應用程式,將由 account 合作夥伴使用者存取的網頁伺服器。The resource partner organization contains the Web servers hosting the Web-based applications that will be accessed by users in the account partner. 這個組織中的系統管理員必須使用 AD FS 管理 snap\ 中建立宣告代表 account 合作夥伴公司他們信任關係的提供者信任。Administrators in this organization must use the AD FS Management snap-in to create claims provider trusts to represent their trust relationships with account partner organizations. 接下來 account 合作夥伴系統管理員必須建立針對每個 account 合作夥伴組織想要信任信賴廠商信任。In turn, the account partner administrator must create relying party trusts for each account partner organization that they want to trust.

此檢查清單會包含所需的部署 Active Directory 同盟服務 (AD FS) 資源合作夥伴組織中的工作。This checklist includes the tasks that are necessary for deploying Active Directory Federation Services (AD FS) in the resource partner organization. 它也包含針對設定所需來建立 one\ 一半聯盟合作關係元件工作。It also includes tasks for configuring the components that are required to establish one-half of a federation partnership.

如果您要部署網站 SSO 設計,您不需要遵循此檢查清單。If you are deploying a Web SSO Design, you do not have to follow this checklist. 不過,您可以完成成功部署檢查清單中的工作的聯盟網路 SSO 設計However, you do have to complete the tasks in this checklist to successfully deploy a Federated Web SSO Design.

重要

請務必 account 合作夥伴公司的系統管理員遵循的指導方針檢查清單︰ 設定 Account 合作夥伴公司以確保所有所需部署工作,將會完成成功半部聯盟合作關係建立第二個Make sure that the administrator of the account partner organization follows the guidance in Checklist: Configuring the Account Partner Organization to ensure that all necessary deployment tasks will be completed to successfully create the second half of the federation partnership

注意

完成此訂單中的檢查清單中的工作。Complete the tasks in this checklist in order. 當參考連結可讓您的程序時,返回本主題之後在您完成該程序中的步驟操作,以便您可以繼續檢查清單中的其餘的工作。When a reference link takes you to a procedure, return to this topic after you complete the steps in that procedure so that you can proceed with the remaining tasks in this checklist.

<span data-ttu-id="60269-114">設定資源合作夥伴組織](media/2b05dce3-938f-4168-9b8f-1f4398cbdb9b.gif)**檢查清單︰ 設定資源合作夥伴公司**</span><span class="sxs-lookup"><span data-stu-id="60269-114">configure resource partner orgChecklist: Configuring the resource partner organization

工作Task 參考資料Reference
設定資源合作夥伴組織 如果今天 production 環境中有 AD FS 1.0 或 1.1 現有的部署,看到資訊,了解如何從您目前的同盟服務的設定移轉到新的 AD FS 同盟服務的權限的連結。If you have an existing AD FS 1.0 or 1.1 deployment in your production environment today, see the link to the right for information about how to migrate settings from your current Federation Service to a new AD FS Federation Service. 如果您在組織中的第一次部署 AD FS 使用 AD FS,您可以略過此步驟後繼續到新的資源合作夥伴公司所設定的相關資訊的檢查清單中的下一個工作。If you are deploying AD FS for the first time in your organization using AD FS, you can skip this step and continue to the next task in this checklist for information about how to set up a new resource partner organization. <span data-ttu-id="60269-120">設定資源合作夥伴組織移轉到 AD FS 計劃](https://technet.microsoft.com/library/ff678044.aspx)configure resource partner orgPlanning a Migration to AD FS
設定資源合作夥伴組織 根據您的部署目標,檢視元件所需的使用者提供聯盟應用程式存取的相關資訊。Based on your deployment goals, review information about the components that are required to provide users with access to the federated applications. <span data-ttu-id="60269-123">設定資源合作夥伴組織提供您 Active Directory 使用者存取您宣告感知應用程式與服務](https://technet.microsoft.com/library/dd807071.aspx)configure resource partner orgProvide Your Active Directory Users Access to Your Claims-Aware Applications and Services

<span data-ttu-id="60269-124">設定資源合作夥伴組織提供您 Active Directory 使用者存取應用程式與其他公司的服務](https://technet.microsoft.com/library/dd807123.aspx)configure resource partner orgProvide Your Active Directory Users Access to the Applications and Services of Other Organizations

<span data-ttu-id="60269-125">設定資源合作夥伴組織提供使用者另一個組織存取您宣告感知應用程式與服務](https://technet.microsoft.com/library/dd807099.aspx)configure resource partner orgProvide Users in Another Organization Access to Your Claims-Aware Applications and Services
設定資源合作夥伴組織 判斷哪一個 AD FS 設計此資源的合作夥伴公司將會與。Determine which AD FS design this resource partner organization will be associated with. <span data-ttu-id="60269-128">設定資源合作夥伴組織網站 SSO 設計](https://technet.microsoft.com/library/dd807033.aspx)configure resource partner orgWeb SSO Design

<span data-ttu-id="60269-129">設定資源合作夥伴組織的聯盟網路 SSO 設計](https://technet.microsoft.com/library/dd807050.aspx)configure resource partner orgFederated Web SSO Design
設定資源合作夥伴組織 檢視不同的應用程式類型,並選擇要部署的應用程式。Review the different application types, and decide which application to deploy. <span data-ttu-id="60269-132">設定資源合作夥伴組織判斷您聯盟應用程式中策略資源合作夥伴](https://technet.microsoft.com/library/dd807077.aspx)configure resource partner orgDetermine Your Federated Application Strategy in the Resource Partner
設定資源合作夥伴組織 部署 AD FS 伺服器在您開始之前,先檢視。1。) 優點和缺點選擇 [Windows 內部資料庫 (WID) 或 SQL Server 儲存 AD FS 設定資料庫 2。) AD FS 部署拓撲類型與他們相關聯的伺服器位置與網路的版面配置建議。Before you begin deploying your AD FS servers, review the; 1.) advantages and disadvantages of choosing either Windows Internal Database (WID) or SQL Server to store the AD FS configuration database 2.) AD FS deployment topology types and their associated server placement and network layout recommendations. <span data-ttu-id="60269-135">設定資源合作夥伴組織判斷您 AD FS 部署拓撲](https://technet.microsoft.com/library/gg982491.aspx)configure resource partner orgDetermine Your AD FS Deployment Topology

<span data-ttu-id="60269-136">設定資源合作夥伴組織AD FS 部署拓撲注意事項](https://technet.microsoft.com/library/gg982489.aspx)configure resource partner orgAD FS Deployment Topology Considerations
設定資源合作夥伴組織 檢查 AD FS 容量計劃指導方針判斷聯盟伺服器和您應該 production 環境中使用聯盟 server proxy 伺服器的適當的數字。Review AD FS capacity planning guidance to determine the proper number of federation server and federation server proxy servers you should use in your production environment. <span data-ttu-id="60269-139">設定資源合作夥伴組織AD FS 伺服器容量的計劃](https://technet.microsoft.com/library/gg749899.aspx)configure resource partner orgPlanning for AD FS Server Capacity
設定資源合作夥伴組織 有效規劃和實作實體拓撲 account 合作夥伴部署,判斷是否 AD FS 設計需要一或多個聯盟伺服器或聯盟的 proxy 伺服器。To effectively plan and implement the physical topology for the account partner deployment, determine whether your AD FS design requires one or more federation servers or federation server proxies. <span data-ttu-id="60269-142">設定資源合作夥伴組織檢查清單︰ 設定好聯盟伺服器](Checklist--Setting-Up-a-Federation-Server.md)configure resource partner orgChecklist: Setting Up a Federation Server

<span data-ttu-id="60269-143">設定資源合作夥伴組織檢查清單︰ 設定好聯盟伺服器 Proxy](Checklist--Setting-Up-a-Federation-Server-Proxy.md)configure resource partner orgChecklist: Setting Up a Federation Server Proxy
設定資源合作夥伴組織 判斷您想要新增到 AD FS 屬性存放區類型。Determine the type of attribute store that you want to add to AD FS. 然後,新增屬性網上商店使用 AD FS 管理 snap\ 中。Then, add the attribute store using the AD FS Management snap-in. <span data-ttu-id="60269-147">設定資源合作夥伴組織的屬性商店角色](../../ad-fs/technical-reference/The-Role-of-Attribute-Stores.md)configure resource partner orgThe Role of Attribute Stores

<span data-ttu-id="60269-148">設定資源合作夥伴組織新增屬性網上商店](../../ad-fs/operations/Add-an-Attribute-Store.md)configure resource partner orgAdd an Attribute Store
設定資源合作夥伴組織 如果您將需要傳送或使用宣告從 account 合作夥伴是使用 AD FS 1.0 或 1.1 同盟服務,請查看連結以了解如何設定 AD FS 資訊的權限舊版 AD FS 交互操作主張。If you will need to send claims to or consume claims from an account partner who is using either an AD FS 1.0 or 1.1 Federation Service, see the link to the right for information about how to configure AD FS to interoperate with previous versions of AD FS. 如果 account 合作夥伴公司也會使用 AD FS 傳送或使用您的組織宣告,您可以略過此步驟,並繼續進行下一個任務檢查清單中。If the account partner organization is also using AD FS to send or consume claims to your organization, you can skip this step and continue with the next task in this checklist. <span data-ttu-id="60269-152">設定資源合作夥伴組織規劃 AD FS 使用的跨平台 1.x](https://technet.microsoft.com/library/ff678040.aspx)configure resource partner orgPlanning for Interoperability with AD FS 1.x
設定資源合作夥伴組織 部署資源合作夥伴組織中的第一個聯盟伺服器之後,請使用 AD FS 管理 snap\ 中建立宣告提供者信任關係。After you deploy the first federation server in the resource partner organization, create a claims provider trust relationship by using the AD FS Management snap-in. 您可以建立宣告提供者信任輸入 account 合作夥伴以手動方式的相關資料,或使用聯盟中繼資料 URL account 合作夥伴公司的系統管理員提供給您。You can create a claims provider trust by entering data about an account partner manually or by using a federation metadata URL that the administrator of the account partner organization provides to you. 您可以使用聯盟中繼資料來自動資源夥伴擷取的資料。You can use the federation metadata to retrieve the data for the resource partner automatically. 注意:如果 account 合作夥伴發行其聯盟中繼資料,或可供您使用的檔案複本,我們建議您先自動擷取的資料就可以節省時間,因為。Note: If the account partner publishes its federation metadata or can provide a file copy of it for you to use, we recommend that you retrieve the data automatically because it can save time. <span data-ttu-id="60269-158">設定資源合作夥伴組織可以廠商信任手動建立](../../ad-fs/operations/Create-a-Relying-Party-Trust.md)configure resource partner orgCreate a Relying Party Trust Manually

<span data-ttu-id="60269-159">設定資源合作夥伴組織建立可以廠商信任使用聯盟中繼資料](../../ad-fs/operations/Create-a-Relying-Party-Trust.md)configure resource partner orgCreate a Relying Party Trust Using Federation Metadata
設定資源合作夥伴組織 根據您的組織的需求,建立一或多個宣告規則集合,連入宣告會通過,AD FS 管理 snap\ 中指定每個宣告提供者信任轉換,或到對應宣告資源合作夥伴在適當地對應。Depending on the needs of your organization, create one or more claim rule sets for each claims provider trust that is specified in the AD FS Management snap-in so that incoming claims will be passed through, transformed, or mapped appropriately to corresponding claims in the resource partner. <span data-ttu-id="60269-162">設定資源合作夥伴組織檢查清單︰ 建立理賠要求規則信任宣告提供者](Checklist--Creating-Claim-Rules-for-a-Claims-Provider-Trust.md)configure resource partner orgChecklist: Creating Claim Rules for a Claims Provider Trust
設定資源合作夥伴組織 宣告描述可能會有一個並不存在,無法建立 (Optional) 將滿足您組織的需求。(Optional) A claim description may have to be created if one does not already exist that will fulfill the needs of your organization. AD FS 包含 AD FS 管理 snap\ 中宣告描述公開的預設設定。AD FS includes a default set of claim descriptions that are exposed in the AD FS Management snap-in. <span data-ttu-id="60269-166">設定資源合作夥伴組織需要新增描述宣告](../../ad-fs/operations/Add-a-Claim-Description.md)configure resource partner orgAdd a Claim Description