使用 SQL Server 聯盟伺服器陣列Federation Server Farm Using SQL Server

適用於:Windows Server 2016、Windows Server 2012 R2Applies To: Windows Server 2016, Windows Server 2012 R2

這個 Active Directory 同盟服務 (AD FS) 拓撲與它不會複寫發電廠每個聯盟伺服器資料,使用 Windows 內部資料庫 (WID) 部署拓撲聯盟伺服器陣列不同。This topology for Active Directory Federation Services (AD FS) differs from the federation server farm using Windows Internal Database (WID) deployment topology in that it does not replicate the data to each federation server in the farm. 改所有聯盟伺服器可讀取和寫入通用資料庫會儲存在位於公司網路中的 Microsoft SQL server 的伺服器上的資料。Instead, all federation servers in the farm can read and write data into a common database that is stored on a server running Microsoft SQL Server that is located in the corporate network.


如果您想要建立 AD FS 發電廠 SQL Server 來儲存您設定的資料的使用,您可以使用 SQL Server 2008 和較新版本,包括 SQL Server 2012,以及 SQL Server 2014。If you want to create an AD FS farm and use SQL Server to store your configuration data, you can use SQL Server 2008 and newer versions, including SQL Server 2012, and SQL Server 2014.

部署注意事項Deployment considerations

本節各種考量有關的目標對象、優點和這部署拓撲相關聯的限制。This section describes various considerations about the intended audience, benefits, and limitations that are associated with this deployment topology.

誰應該使用此拓撲?Who should use this topology?

  • 大型的組織超過 100 信任關係,必須為其內部使用者和外部使用者單一 sign\ 上 (SSO) 存取聯盟應用程式或服務提供使用Large organizations with more than 100 trust relationships that need to provide both their internal users and external users with single sign-on (SSO) access to federated application or services

  • 組織已經使用 SQL Server,並且想要利用其現有的工具和專業Organizations that already use SQL Server and want to take advantage of their existing tools and expertise

使用這個拓撲的好處為何?What are the benefits of using this topology?

  • 支援信任關係的數字越大 (more than 100)Support for larger numbers of trust relationships (more than 100)

  • 支援權杖重播偵測 (a security feature) 和成品解析度 \ (安全性判斷提示標記語言 (SAML) 2.0 的一部分 protocol)Support for token replay detection (a security feature) and artifact resolution (part of the Security Assertion Markup Language (SAML) 2.0 protocol)

  • 支援 SQL Server 的完整優點資料庫鏡像、容錯、報告] 下方,和管理工具Support for the full benefits of SQL Server, such as database mirroring, failover clustering, reporting, and management tools

使用這個拓撲限制為何?What are the limitations of using this topology?

  • 這個拓撲預設不提供資料庫冗餘。This topology does not provide database redundancy by default. 聯盟伺服器陣列有 SQL Server 拓撲聯盟伺服器陣列有 WID 拓撲會自動複製 WID 資料庫陣列中每個聯盟伺服器上的,但包含份資料庫Although a federation server farm with WID topology automatically replicates the WID database on each federation server in the farm, the federation server farm with SQL Server topology contains only one copy of the database


SQL Server 支援許多不同的資料與應用程式冗餘選項,包括容錯,請稍後及 SQL Server 複寫數種不同類型。SQL Server supports many different data and application redundancy options including failover clustering, database mirroring, and several different types of SQL Server replication.

Microsoft 的資訊技術 (IT) 部門使用 SQL Server 資料庫鏡像 high\ 安全 (synchronous) 模式和容錯提供 high\ 可用性支援 SQL Server 執行個體。The Microsoft Information Technology (IT) department uses SQL Server database mirroring in high-safety (synchronous) mode and failover clustering to provide high-availability support for the SQL Server instance. Microsoft AD FS product 小組尚未經過測試 SQL Server 交易 (peer-to-peer) 及合併複寫。SQL Server transactional (peer-to-peer) and merge replication have not been tested by the AD FS product team at Microsoft. 如需 SQL Server 的詳細資訊,請查看高可用性方案概觀選取適當的︰ 複寫輸入For more information about SQL Server, see High Availability Solutions Overview or Selecting the Appropriate Type of Replication.

支援的 SQL Server 版本Supported SQL Server Versions

AD FS 在 Windows Server 2012 R2 的支援下列 SQL server 版本:The following SQL server versions are supported with AD FS in Windows Server 2012 R2:

  • SQL Server 2008 \ 日 R2SQL Server 2008 / R2

  • SQL Server 2012SQL Server 2012

  • SQL Server 2014SQL Server 2014

伺服器配置建議位置與網路Server placement and network layout recommendations

類似的 WID 拓撲聯盟伺服器陣列聯盟伺服器的所有設定為使用一個叢集網域名稱系統 (DNS) 名稱 \(代表同盟服務 name\)和網路負載平衡 (NLB) 叢集組態的一部分一個叢集 IP 位址。Similar to the federation server farm with WID topology, all of the federation servers in the farm are configured to use one cluster Domain Name System (DNS) name (which represents the Federation Service name) and one cluster IP address as part of the Network Load Balancing (NLB) cluster configuration. 這可協助 NLB 主機配置 client 要求的個人聯盟伺服器。This helps the NLB host allocate client requests to the individual federation servers. 聯盟伺服器 proxy 可用於 proxy 伺服器聯盟陣列 client 請求。Federation server proxies can be used to proxy client requests to the federation server farm.

下圖顯示虛構 Contoso 醫藥公司部署其聯盟具有伺服器陣列 SQL Server 拓撲公司網路中的方式。The following illustration shows how the fictional Contoso Pharmaceuticals company deployed its federation server farm with SQL Server topology in the corporate network. 它也示範如何該公司設定周邊網路存取權的 DNS 伺服器,使用適用於企業網路 NLB 叢集、相同叢集 DNS 名稱 (fs.contoso.com) 其他 NLB 主機與兩個 web 應用程式 proxy (wap1 and wap2)。It also shows how that company configured the perimeter network with access to a DNS server, an additional NLB host that uses the same cluster DNS name (fs.contoso.com) that is used on the corporate network NLB cluster, and with two web application proxies (wap1 and wap2).

使用 SQL server 陣列

如需有關如何聯盟伺服器或網路應用程式的 proxy 設定使用您的網路環境,查看 [名稱解析需求」一節中AD FS 需求計劃 Web 應用程式 Proxy 基礎結構 (WAP)For more information about how to configure your networking environment for use with federation servers or web application proxies, see “Name Resolution Requirements” section in AD FS Requirements and Plan the Web Application Proxy Infrastructure (WAP).

可用性選項 SQL Server 農田High Availability Options for SQL Server Farms

在 Windows Server 2012 R2,AD FS 有兩個新選項支援可用性 AD FS 農場使用 SQL Server 中。In Windows Server 2012 R2, AD FS there are two new options to support high availability in AD FS farms using SQL Server.

  • 支援 SQL Server AlwaysOn 可用性群組Support for SQL Server AlwaysOn Availability Groups

  • 支援使用 SQL Server 合併複寫分散可用性Support for geographically distributed high availability using SQL Server merge replication

本節每個選項,它們分別克服哪些問題,以及一些重要事項決定部署的選項。This section describes each of these options, what problems they respectively solve, and some key considerations for deciding which options to deploy.


使用 Windows 內部資料庫 (WID) AD FS 農場備援基本資料 read\ 寫主要聯盟伺服器節點上的存取權與 read\ 存取第二個節點上。AD FS farms that use Windows Internal Database (WID) provide basic data redundancy with read/write access on the primary federation server node and read-only access on secondary nodes. 這可用於地理位置本機或分散的拓撲。This can be used in a geographically local or a geographically distributed topology.

當使用 WID 會注意到以下限制︰When using WID be aware of the following limitations:

  • 如果您依賴 100 或較少廠商信任,WID 發電廠的 30 聯盟伺服器的上限。A WID farm has a limit of 30 federation servers if you have 100 or fewer relying party trusts.
  • WID 發電廠不支援權杖重播偵測或成品解析度 \(的安全性判斷提示標記語言 (SAML) protocol\ 一部分)。A WID farm does not support token replay detection or artifact resolution (part of the Security Assertion Markup Language (SAML) protocol).

下表使用 WID 發電廠提供摘要。The following table provides a summary for using a WID farm.

1 -100 資源點數信任1 - 100 RP Trusts 超過 100 資源點數信任More than 100 RP Trusts
1 -30 AD FS 節點1 - 30 AD FS Nodes WID 支援WID Supported 不支援使用 WID -SQL 需要Not supported using WID - SQL Required
超過 30 AD FS 節點More than 30 AD FS Nodes 不支援使用 WID -SQL 需要Not supported using WID - SQL Required 不支援使用 WID -SQL 需要Not supported using WID - SQL Required

AlwaysOn 可用性群組AlwaysOn Availability Groups


AlwaysOn 可用性群組帶來 SQL Server 2012 和提供新的方式來建立的可用性 SQL Server 執行個體。AlwaysOn Availability groups were introduced in SQL Server 2012 and provide a new way to create a high availability SQL Server instance. AlwaysOn 可用性群組結合叢集和資料庫鏡像冗餘和容錯移轉 SQL 執行個體層和資料庫層級兩者的項目。AlwaysOn Availability groups combine elements of clustering and database mirroring for redundancy and failover at both the SQL instance layer and the database layer. 然而先前的可用性選項 AlwaysOn 可用性群組不需要一般的儲存空間 \(或存放區 network\)資料庫層級。Unlike previous high availability options, AlwaysOn Availability groups do not require a common storage (or storage area network) at the database layer.

可用性群組所組成主要複本 \(read\ 寫主要 databases\ 一組)和 1 到 4 個可用性複本 \(的對應次要 databases\ 集)。An availability group is comprised of a primary replica (a set of read-write primary databases) and one to four availability replicas (sets of corresponding secondary databases). 可用性群組支援單一 read\ 寫複製 \ (主要 replica),以及 1 到 4 個僅限 read\ 可用性複本。The availability group supports a single read-write copy (the primary replica), and one to four read-only availability replicas. 每個可用性複本必須位於不同的單一的 Windows Server 容錯 (WSFC) 叢集節點。Each availability replica must reside on a different node of a single Windows Server Failover Clustering (WSFC) cluster. 如需有關 AlwaysOn 可用性群組查看AlwaysOn 可用性群組概觀 (SQL Server)For more information on AlwaysOn Availability groups see Overview of AlwaysOn Availability Groups (SQL Server).

AD FS SQL Server 發電廠節點觀點,AlwaysOn 可用性群組會取代為原則的單一 SQL Server 執行個體 \ 日成品資料庫。From the perspective of the nodes of an AD FS SQL Server farm, the AlwaysOn Availability group replaces the single SQL Server instance as the policy / artifact database. 可用性群組其實是何種 client \ 連接 SQL (AD FS 的安全性權杖 service) 使用。The availability group listener is what the client (the AD FS security token service) uses to connect to SQL.

下圖顯示 AD FS SQL Server 發電廠 AlwaysOn 可用性群組。The following diagram shows an AD FS SQL Server Farm with AlwaysOn Availability group.

使用 SQL server 陣列


AlwaysOn 可用性群組需要 SQL Server 執行個體存在於 Windows Server 容錯 (WSFC) 節點。AlwaysOn Availability groups require that the SQL Server instances reside on Windows Server Failover Clustering (WSFC) nodes.


只有一個可用性複本可做為自動容錯移轉目標,其他三個將會依賴手動錯誤後的移轉。Only one availability replica can act as an automatic failover target, the other three will rely on manual failovers.

主要部署注意事項Key Deployment Considerations

如果您打算 SQL Server 合併複寫搭配使用的可用性 AlwaysOn 群組,請記下在」SQL Server 合併複寫 AD FS 使用的按鍵部署考量」如下所述的問題。If you plan to use AlwaysOn Availability groups in combination with SQL Server merge replication, please take note of the issues described under “Key Deployment Considerations for using AD FS with SQL Server Merge Replication” below. 尤其當包含是複寫訂閱資料庫 AlwaysOn 可用性群組失敗,複寫裝機費失敗。In particular, when an AlwaysOn availability group containing a database that is a replication subscriber fails over, the replication subscription fails. 若要繼續複寫,複寫系統管理員必須手動重新設定訂戶。To resume replication, a replication administrator must manually reconfigure the subscriber. 看 SQL Server 特定問題的複寫訂閱和 AlwaysOn 可用性群組 (SQL Server)和整體支援聲明 AlwaysOn 可用性群組複寫選項,在複寫、歷程、變更擷取的資料,及 AlwaysOn 可用性群組 (SQL Server)See the SQL Server description of specific issue at Replication Subscribers and AlwaysOn Availability Groups (SQL Server) and overall support statements for AlwaysOn Availability groups with replication options at Replication, Change Tracking, Change Data Capture, and AlwaysOn Availability Groups (SQL Server).

設定 AD FS 使用 AlwaysOn 可用性群組Configuring AD FS to use an AlwaysOn Availability group

AD FS 發電廠設定 AlwaysOn 可用性群組需要稍微 AD FS 部署程序修改:Configuring an AD FS farm with AlwaysOn Availability groups requires a slight modification to the AD FS deployment procedure:

  1. 必須先建立的資料庫您想要備份,您可以設定 AlwaysOn 可用性群組。The databases you wish to back up must be created before the AlwaysOn Availability groups can be configured. AD FS 建立它資料庫設定與初始設定新的 AD FS SQL Server 發電廠的第一個同盟服務節點的一部分。AD FS creates its databases as part of the setup and initial configuration of the first federation service node of a new AD FS SQL Server farm. AD FS 組態的一部分,您必須指定 SQL 連接字串,因此您將需要設定直接連接至 SQL 執行個體的第一個 AD FS 發電廠節點 \(這是只 temporary\)。As part of the AD FS configuration, you must specify an SQL connection string, so you will have to configure the first AD FS farm node to connect to a SQL instance directly (this is only temporary). 特定指導方針設定 AD FS 發電廠,包括設定 AD FS 發電廠節點 SQL server 連接字串,請查看設定聯盟伺服器For specific guidance on configuring an AD FS farm, including configuring an AD FS farm node with a SQL server connection string, see Configure a Federation Server.

  2. 一旦建立 AD FS 資料庫,指派給群組 AlwaysOn 可用性建立使用 SQL Server 工具常見 TCPIP 其實及處理建立和設定的可用性群組 (SQL Server)Once the AD FS databases have been created, assign them to AlwaysOn Availability groups and create the common TCPIP listener using SQL Server tools and process at Creation and Configuration of Availability Groups (SQL Server).

  3. 最後,使用 PowerShell 編輯 AD FS 屬性更新 SQL 連接字串使用 AlwaysOn 可用性群組其實 DNS 地址。Finally, use PowerShell to edit the AD FS properties to update the SQL connection string to use the DNS address of the AlwaysOn Availability group’s listener.

    範例更新 SQL 連接字串 AD FS 原則資料庫 PSH 命令:Example PSH commands to update the SQL connection string for the AD FS policy database:

    PS:\>$temp= Get-WmiObject -namespace root/ADFS -class SecurityTokenService  
    PS:\>$temp.ConfigurationdatabaseConnectionstring=”data source=<SQLCluster\SQLInstance>; initial catalog=adfsconfiguration;integrated security=true”  
  4. 範例更新 SQL 連接字串 AD FS 原則資料庫 PSH 命令:Example PSH commands to update the SQL connection string for the AD FS policy database:

    PS:\> Set-AdfsProperties –artifactdbconnection ”Data source=<SQLCluster\SQLInstance >;Initial Catalog=AdfsArtifactStore;Integrated Security=True”  

SQL Server 合併複寫SQL Server Merge Replication

AD FS 使用下列特性原則資料冗餘也引進了 SQL Server 2012,可讓合併複寫:Also introduced in SQL Server 2012, merge replication allows for AD FS policy data redundancy with the following characteristics:

  • 讀取和寫入所有節點上的功能 \ (而不只是 primary)Read and write capability on all nodes (not just the primary)

  • 小大量非同步複製到避免延遲系統資料Smaller amounts of data replicated asynchronously to avoid introducing latency to the system

下圖顯示地理位置備援 AD FS SQL Server 農場合併複寫 \(發行者 1、2 subscribers\):The following diagram shows a geographically redundant AD FS SQL Server farms with merge replication (1 publisher, 2 subscribers):

使用 SQL server 陣列

AD FS 使用 SQL Server 合併複寫鍵部署考量 \(請注意圖表 above\ 中的數字)Key Deployment Considerations for using AD FS with SQL Server Merge Replication (note numbers in the diagram above)

使用 SQL Server 合併複寫如何設定 AD FS 詳細指示,請查看安裝地理備援 SQL Server 複寫與For more detailed instructions on how to configure AD FS to use a SQL Server merge replication, see Setup Geographic Redundancy with SQL Server Replication.

也了See Also

AD FS 部署拓撲計劃Plan Your AD FS Deployment Topology
在 Windows Server 2012 R2 的 AD FS 設計指南AD FS Design Guide in Windows Server 2012 R2