檢視資源合作夥伴聯盟伺服器的角色Review the Role of the Federation Server in the Resource Partner

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

聯盟伺服器資源合作夥伴組織攔截收到安全性權杖中所傳送 account 聯盟伺服器的驗證簽署,並再問題自己的目的地 Web\ 型應用程式的安全性權杖。The federation server in the resource partner organization intercepts incoming security tokens that are sent by an account federation server, validates and signs them, and then issues its own security tokens that are destined for the Web-based application.

注意

當聯盟的使用者存取 Web\ 為基礎的應用程式使用網頁瀏覽器時,聯盟伺服器資源合作夥伴組織中的組建將新的驗證 cookie,並將它寫入瀏覽器。When federated users use their Web browsers to access Web-based applications, the federation server in the resource partner organization builds a new authentication cookie and writes it to the browser. 此 cookie 可讓 single\ sign\ 上 (SSO) 功能,因此,不需要重新登入聯盟伺服器 account 合作夥伴中,當使用者嘗試存取不同 Web\ 型應用程式資源合作夥伴使用者。This cookie enables single-sign-on (SSO) capabilities so that users do not have to log on again at the federation server in the account partner when the users attempt to access different Web-based applications in the resource partner.

在 [網站 SSO 設計,必須安裝至少一個聯盟伺服器周邊網路中。In the Web SSO design, at least one federation server must be installed in the perimeter network. 聯盟網路 SSO 設計,有必須安裝 account 合作夥伴公司的企業網路至少一個聯盟伺服器並安裝在公司網路資源合作夥伴公司的至少一個聯盟伺服器。In the Federated Web SSO design, there must be at least one federation server installed in the corporate network of the account partner organization and at least one federation server installed in the corporate network of the resource partner organization.

注意

您可以設定資源合作夥伴組織中聯盟伺服器電腦之前,您必須先將電腦加入資源合作夥伴組織中的任何 Active Directory domain。Before you can set up a federation server computer in the resource partner organization, you must first join the computer to any Active Directory domain in the resource partner organization. 如需詳細資訊,請查看檢查清單︰ 設定好聯盟伺服器For more information, see Checklist: Setting Up a Federation Server.

也了See Also

Windows Server 2012 中的 AD FS 設計指南AD FS Design Guide in Windows Server 2012