建立獨立聯盟伺服器Create a Stand-Alone Federation Server

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

您安裝同盟服務的角色,並在電腦上設定所需的憑證之後,您就可以設定電腦成為聯盟伺服器。After you install the Federation Service role service and configure the required certificates on a computer, you are ready to configure the computer to become a federation server. 成為聯盟 stand\ 只伺服器設定電腦,您可以使用下列程序。You can use the following procedure to set up the computer to become a stand-alone federation server. 建立 stand\ 只聯盟伺服器的動作也會建立新的同盟服務。The act of creating a stand-alone federation server also creates a new Federation Service. 您使用 AD FS 聯盟伺服器設定精靈建立聯盟伺服器。You do create a federation server with the AD FS Federation Server Configuration Wizard.

注意

聯盟網路 Single-Sign-On (SSO) 設計,您必須至少一個聯盟伺服器 account 合作夥伴組織和資源合作夥伴組織中的至少一個聯盟伺服器。For the Federated Web Single-Sign-On (SSO) design, you must have at least one federation server in the account partner organization and at least one federation server in the resource partner organization. 如需詳細資訊,請查看放置聯盟伺服器For more information, see Where to Place a Federation Server.

資格在系統管理員,或相當於、在本機電腦上的最低需求完成此程序。Membership in Administrators, or equivalent, on the local computer is the minimum required to complete this procedure. 檢視詳細資料使用適當的帳號,並群組成員資格,本機和網域預設群組\ (go.microsoft.com\ fwlink\ 方式 http://// # / 嗎?LinkId\ = 83477)。Review details about using the appropriate accounts and group memberships at Local and Domain Default Groups (http://go.microsoft.com/fwlink/?LinkId=83477).

若要建立 stand\ 只聯盟伺服器To create a stand-alone federation server

  1. 有兩種方法可以開始 AD FS 聯盟伺服器設定精靈。There are two ways to start the AD FS Federation Server Configuration Wizard. 若要開始精靈中,執行下列其中一個動作:To start the wizard, do one of the following:

    • 同盟服務角色服務安裝完成後,開放 AD FS 管理 snap\ 中,按一下AD FS 聯盟伺服器設定精靈上的連結概觀頁面或控制項窗格。After the Federation Service role service installation is complete, open the AD FS Management snap-in and click the AD FS Federation Server Configuration Wizard link on the Overview page or in the Actions pane.

    • 依照本身需求加以安裝精靈完成,開放 Windows 檔案總管] 之後,瀏覽至C:\Windows\ADFS資料夾,然後 double\ 按FsConfigWizard.exeAnytime after the setup wizard is complete, open Windows Explorer, navigate to the C:\Windows\ADFS folder, and then double-click FsConfigWizard.exe.

  2. 歡迎頁面上,確認建立新的同盟服務已選取,然後按一下 [下一步On the Welcome page, verify that Create a new Federation Service is selected, and then click Next.

  3. 選取 Stand-只或發電廠部署頁面上,按一下 [ Stand\ 只聯盟伺服器,然後按一下 [下一步On the Select Stand-Alone or Farm Deployment page, click Stand-alone federation server, and then click Next.

    重要

    當您選取 AD FS 聯盟伺服器設定精靈中的 [Stand\ 只聯盟伺服器] 選項時,與此同盟服務相關的服務帳號將會自動指派給網路服務 account。When you select the Stand-alone federation server option in the AD FS Federation Server Configuration Wizard, the service account associated with this Federation Service will automatically be assigned to the NETWORK SERVICE account. 僅限建議的情形評估 AD FS 在實驗室測試環境中使用服務 account 網路的服務。Using NETWORK SERVICE as the service account is only recommended in situations where you are evaluating AD FS in a test lab environment. 如果您想要部署聯盟伺服器 production 環境中的使用 [Stand\ 只聯盟伺服器] 選項,請務必,您可以要求波此新同盟服務專用更適當服務過去變更此服務 account。If you intend to use the Stand-alone federation server option to deploy a federation server in a production environment, it is important that you change this service account to a more appropriate service account that can be dedicated to serving requests for this new Federation Service. 變更服務帳號以外的其他網路服務過去將會減少可能攻擊能否則讓您聯盟伺服器惡意攻擊。Changing the service account to an account other than NETWORK SERVICE will mitigate possible attack vectors that would otherwise make your federation server vulnerable to malicious attacks.

  4. 同盟服務名稱指定頁面上,確認SSL 憑證,會顯示正確。On the Specify the Federation Service Name page, verify that the SSL certificate that is showing is correct. 如果不行,請選取適當的憑證的SSL 憑證清單中。If not, select the appropriate certificate from the SSL certificate list.

    這個憑證也從安全通訊端層 (SSL) 設定為預設值的網站。This certificate is generated from the Secure Sockets Layer (SSL) settings for the Default Web Site. 如果只有一個 SSL 憑證設定預設值的網站,該憑證呈現及自動選取 [使用。If the Default Web Site has only one SSL certificate configured, that certificate is presented and automatically selected for use. 多個 SSL 憑證的網站,預設設定,如果以下列出這些所有憑證,您必須從他們中選取。If multiple SSL certificates are configured for the Default Web Site, all those certificates are listed here and you must select from among them. 不 SSL 設定為預設值的網站時,也可在本機電腦上的個人化的憑證存放區憑證的清單。If there are no SSL settings configured for the Default Web Site, the list is generated from the certificates that are available in the personal certificates store on the local computer.

    注意

    精靈將不允許您若 SSL 憑證已設定為 IIS 覆寫憑證。The wizard will not allow you to override the certificate if an SSL certificate is configured for IIS. 這樣可確保任何預期會保留先前 IIS 組態 SSL 憑證。This ensures that any intended prior IIS configuration for SSL certificates is preserved. 若要替代這項限制時,您可以移除憑證或重新設定以手動方式與 IIS 管理主控台。To work around this restriction, you can remove the certificate or reconfigure manually it with the IIS Management Console.

  5. 如果您已經選取 AD FS 資料庫存在,現有 AD FS 設定資料庫偵測到頁面隨即顯示。If the AD FS database that you selected already exists, the Existing AD FS Configuration Database Detected page appears. 發生這種情形,如果按一下Delete 資料庫,然後按一下 [If that occurs, click Delete database, and then click Next.

    警告

    只有當您確定此 AD FS 資料庫中的資料並不重要或不使用正式作業聯盟伺服器陣列中,選取此選項。Select this option only when you are sure that the data in this AD FS database is not important or that it is not used in a production federation server farm.

  6. 適用於設定準備頁面上,檢視詳細資料。On the Ready to Apply Settings page, review the details. 若出現正確設定,請按一下下一步來設定 AD FS 使用這些設定。If the settings appear to be correct, click Next to begin configuring AD FS with these settings.

  7. 設定結果頁面上,檢視結果。On the Configuration Results page, review the results. 所有的設定步驟完成時,按關閉以結束精靈。When all the configuration steps are finished, click Close to exit the wizard.

其他參考資料Additional references

檢查清單︰ 設定聯盟伺服器Checklist: Setting Up a Federation Server