適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

此屬性存放區的角色The Role of Attribute Stores

Active Directory 同盟服務使用的字詞 」 屬性商店 「 參考目錄或資料庫組織用來儲存其帳號,其相關聯的屬性的值。Active Directory Federation Services uses the term “attribute stores” to refer to directories or databases that an organization uses to store its user accounts and their associated attribute values. 它的身分提供者組織中設定之後,AD FS 從存放區擷取這些屬性的值,並建立宣告,根據該資訊,以便 Web 應用程式或服務裝載信賴的派對組織中可以做出適當的授權,只要聯盟使用者 \ 嘗試應用程式或服務存取 (account 其會儲存在身分提供者 organization\ 使用者)。After it is configured in an identity provider organization, AD FS retrieves these attribute values from the store and creates claims based on that information so that a Web application or service that is hosted in a relying party organization can make the appropriate authorization decisions whenever a federated user (a user whose account is stored in the identity provider organization) attempts to access the application or service.

如需有關如何專宣告,請查看宣告角色For more information about how claims are generated, see The Role of Claims.

如何儲存屬性符合使用 AD FS 部署目標How attribute stores fit in with your AD FS deployment goals

使用者屬性存放區的位置,以及位置從中驗證使用者判斷您如何設計支援的使用者身分 AD FS。The location of the user attribute store and the location from which users authenticate determine how you design AD FS to support the user identities. 根據屬性存放區的位置,讓使用者將會存取應用程式 \ (內部網路或 Internet\),您可以使用其中一項下列部署目標:Depending on where the attribute store is located and where users will access the application (in an intranet or on the Internet), you can use one of the following deployment goals:

您可以根據屬性存放區的位置,您的組織其他需求結合幾個部署目標以完成部署 AD FS 的設計。Depending on attribute store placement and other requirements of your organization, you can combine several of these deployment goals to complete the design of your AD FS deployment.

屬性 AD FS 所支援的商店Attribute stores that are supported by AD FS

AD FS 支援各種 directory 和資料庫儲存,您可以使用解壓縮 administrator\ 定義屬性的值與填入主張使用這些值。AD FS supports a wide range of directory and database stores that you can use for extracting administrator-defined attribute values and populating claims with those values. AD FS 支援的任何下列目錄或資料庫屬性商店:AD FS supports any of the following directories or databases as attribute stores:

  • 在 Windows Server 2003 active Directory Active Directory Domain 服務 (AD DS) Windows Server 2008、 Windows Server 2012 和 2012 R2 中 AD DS 和 Windows Server 2016。Active Directory in Windows Server 2003, Active Directory Domain Services (AD DS) in Windows Server 2008, AD DS in Windows Server 2012 and 2012 R2, and Windows Server 2016.

  • 所有的 Microsoft SQL Server 2005、 SQL Server 2008、 SQL Server 2012、 SQL Server 2014,以及 SQL Server 2016 的版本All editions of Microsoft SQL Server 2005, SQL Server 2008, SQL Server 2012, SQL Server 2014, and SQL Server 2016

  • 自訂屬性存放區Custom attribute stores