檢視中 Account 合作夥伴聯盟伺服器角色Review the Role of the Federation Server in the Account Partner

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

在 Active Directory 同盟服務 (AD FS) 聯盟伺服器的安全性權杖發行者功能。A federation server in Active Directory Federation Services (AD FS) functions as a security token issuer. 聯盟伺服器產生宣告型群組清單儲存在本機屬性的值,並,讓使用者可以順暢地進行存取 Web\ browser\ 型應用程式到安全性權杖套件它們 \(使用單一 sign\ 上 (SSO)) 裝載資源合作夥伴組織中。A federation server generates claims based on account values that reside in a local attribute store and packages them into security tokens so that users can seamlessly access Web-browser-based applications (using single sign-on (SSO)) that are hosted in a resource partner organization.

注意

當您的使用者存取聯盟應用程式使用網頁瀏覽器時,聯盟伺服器會自動維護他們登入的狀態該 Web\ browser\ 型應用程式的使用者問題 cookie。When your users access federated applications by using a Web browser, a federation server automatically issues cookies to the users to maintain their logon status for that Web-browser-based application. 這些 cookie 包含宣告使用者。These cookies include claims for the users. Cookie 可以讓 SSO 功能,讓使用者不必輸入認證每次瀏覽不同的 Web\ browser\ 型應用程式,在資源合作夥伴。The cookies enable SSO capabilities so that the users do not have to enter credentials each time that they visit different Web-browser-based applications in the resource partner.

在 [網站 SSO 設計,周邊網路與網際網路存取應用程式的使用者想要的組織必須安裝聯盟伺服器 proxy 周邊網路中。In the Web SSO design, organizations with a perimeter network that want Internet users to have access to applications must install a federation server proxy in the perimeter network. 聯盟網路 SSO 設計,有必須安裝 account 合作夥伴公司的企業網路至少一個聯盟伺服器並安裝在公司網路資源合作夥伴公司的至少一個聯盟伺服器。In the Federated Web SSO design, there must be at least one federation server installed in the corporate network of the account partner organization and at least one federation server installed in the corporate network of the resource partner organization.

注意

您可以設定 account 合作夥伴組織聯盟伺服器電腦之前,您必須第一次將電腦加入任何位置使用聯盟伺服器來驗證使用者的樹系的 Active Directory 森林中的網域。Before you can set up a federation server computer in the account partner organization, you must first join the computer to any domain in the Active Directory forest where the federation server will be used to authenticate users from that forest. 如需詳細資訊,請查看檢查清單︰ 設定好聯盟伺服器For more information, see Checklist: Setting Up a Federation Server.

也了See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012