ADFS Sizing

Team

I am planning to build ADFS 3.0 & I would like to have High Availability for ADFS Servers , there are almost 17000 users who need to access the O365 service , Could you please help on this ?

sizing calculator 

can I use SQL for ADFS Database or WID?

Please give more details on this.

Thanks 

August 29th, 2015 12:10pm

I assume that Office365 will be the only relying party trust. So you can go with a very simple deployment.

  • 2 WAP (proxies) - with a load balancer on the front of the public VIP
  • 2 ADFS servers with WID - with a load balancer on the front of the private VIP

You can go with WID. You won't be able to use the SAML artifact resolution (not used for O365 anyways) nor the embedded token replay attack detection. WID is already "highly available" since it will be running on each ADFS server without configuring anything special. This is explained in details here:

  • Federation Server Farm Using WID and Proxies https://technet.microsoft.com/en-us/library/dn554244.aspx

Note that if you don't care about Windows Integrated Authentication type of SSO, you can also looking at using just Azure AD and don't even deploy anything on premises. But it means that even users on domain joined machines will have to enter their credentials the first time they want to use Office 365 everyday...

Free Windows Admin Tool Kit Click here and download it now
August 29th, 2015 7:44pm

Thanks Pierre for sharing the info.
 
Just want to remind that we mainly focus on ADDS here, there is not too much about ADFS aspect in this forum.
 
For ADFS related questions, we recommend you to post in the dedicated forum below, there you should get more experienced responses:
 
https://social.msdn.microsoft.com/Forums/vstudio/en-US/home?forum=Geneva
 
The reason why we recommend posting appropriately is you will get the most qualified pool of respondents, and other partners who read the forums regularly can either share their knowledge or learn from your interaction with us. Thank you for your understanding.
 

Regards,

Eth

September 1st, 2015 4:09am

Well... Geneva is on the MSDN part. However, ADFS is an infrastructure component. It's an IT Pro product, not a dev one. Not even mentioning that there is no way to find the Geneva forum by typing ADFS in a search. And on the top of this, ADFS.. AD FS.. AD and D stands for Directory :) Hence it makes a bit of sense to ask the question here. I suggest to open a new forum called Active Directory Federation Services on TechNet. What do you think?

Free Windows Admin Tool Kit Click here and download it now
September 1st, 2015 11:24am

I agree with this.
 
We will submit this information through our internal channel. Thank you for the feedback Pierre!
 

Regards,

Eth

September 1st, 2015 11:12pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics