Planning for Single Sign-On with AD FS

For organizations that maintain an internal Active Directory deployment, implementing single sign-on (SSO) is typically a high priority, because this provides the most seamless experience for Lync Online users. SSO enables each user to log on to a client system one time with Active Directory credentials, and access both Lync Online and on-premise resources without being prompted for additional credentials. To allow this functionality, Active Directory must first be prepared for SSO, and Active Directory Federated Services must also be installed on-premise and configured for federation with the Lync Online organization.

Specifically, the deployment of SSO for Lync Online requires the following components:

• Active Directory must be deployed on-premise using Windows 2003 or higher, with a functional level of either mixed or native mode.

• An AD FS 2.0 instance involving at least one federation server must be deployed on-premise, using Windows Server 2008 or higher. If users will be connecting to Lync Online from outside the network, at least one AD FS proxy is also required, and should be installed in a DMZ network.

• The Microsoft Online Services Module for Windows PowerShell must be installed and configured to establish a trust with Lync Online.

• All required updates for Office 365 must be installed on client systems.

The following sections take a closer look at these requirements as part of the planning process for SSO.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset