{"id":152,"date":"2022-02-23T10:37:00","date_gmt":"2022-02-23T02:37:00","guid":{"rendered":"https:\/\/www.ruianding.com\/blog\/?p=152"},"modified":"2023-08-31T01:51:13","modified_gmt":"2023-08-30T17:51:13","slug":"instruction-of-deploy-a-new-primary-adfs-server","status":"publish","type":"post","link":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/","title":{"rendered":"Instruction of Deploy a New Primary ADFS Server"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"1-install-the-ssl-certificate\">1. Install the SSL Certificate<\/h2>\n\n\n\n<p>Prepare your new primary ADFS server. Join the primary ADFS server to your domain. Install your&nbsp;<strong>SSL certificate<\/strong>&nbsp;and import the certificate to the local computer&#8217;s certificates personal store.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\" alt=\"\" class=\"wp-image-156\" width=\"755\" height=\"198\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"2-create-the-adfs-service-account\">2. Create the ADFS Service Account<\/h2>\n\n\n\n<p><strong><em>(Recommend)<\/em><\/strong>&nbsp;Move to Domain Controller, create a new ADFS Service Account, make sure this user account is added to the local administrators group of your AD FS server.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-24.png\" alt=\"\" class=\"wp-image-157\" width=\"393\" height=\"339\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"387\" height=\"336\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-25.png\" alt=\"\" class=\"wp-image-158\"\/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Otherwise, we can create and use a&nbsp;<strong>Managed Service Account<\/strong>&nbsp;instead of manully creating a user. And the Active Directory Federation Service is running under the above ADFS service account.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"3-set-service-principal-name-for-the-service-account\">3. Set Service Principal Name for the Service Account<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"31-add-the-spn-option-1-use-powershell-command\">3.1 Add the SPN (Option 1: Use PowerShell Command)<\/h3>\n\n\n\n<p><strong><em>(Important)<\/em><\/strong>&nbsp;Set the SPN (Service Principal Name) for this service account. By running the following PowerShell command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>setspn -a host\/&lt;server name&gt; &lt;service account&gt;\nsetspn -a http\/&lt;server name&gt; &lt;service account&gt;\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-26.png\" alt=\"\" class=\"wp-image-167\" width=\"758\" height=\"185\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"32-add-the-spn-option-2-manually-add-by-the-attribute-editor\">3.2 Add the SPN (Option 2: Manually Add through the Attribute Editor)<\/h3>\n\n\n\n<p>Go to&nbsp;<strong>Active Directory Users and Computers<\/strong>&nbsp;&gt; Click&nbsp;<strong>View<\/strong>&nbsp;&gt;&nbsp;<strong>Mark Advanced Features<\/strong>&nbsp;&gt; right click this service account &gt;&nbsp;<strong>Properties<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-27.png\" alt=\"\" class=\"wp-image-168\" width=\"265\" height=\"178\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized is-style-default\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-29.png\" alt=\"\" class=\"wp-image-171\" width=\"430\" height=\"370\"\/><\/figure>\n\n\n\n<p>Open&nbsp;<strong>Attribute Editor<\/strong>&nbsp;tab &gt; Find&nbsp;<strong>servicePrincipalName<\/strong>&nbsp;attribute &gt; Double click the attribute &gt; Add host\/http entries in it &gt; Click&nbsp;<strong>Add<\/strong>&nbsp;&gt; Click&nbsp;<strong>OK<\/strong>&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-30.png\" alt=\"\" class=\"wp-image-176\" width=\"279\" height=\"370\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-31.png\" alt=\"\" class=\"wp-image-177\" width=\"288\" height=\"394\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"4-add-the-active-directory-federation-service-role\">4. Add the Active Directory Federation Service Role<\/h2>\n\n\n\n<p>Move to the ADFS Server, add Server Role &#8220;<strong>Active Directory Federation Service<\/strong>&#8221; by&nbsp;<strong>Server Manager<\/strong>.&nbsp;After server role has been added, we will continue to &#8220;<strong>Configure the federation service at the server<\/strong>&#8220;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-32.png\" alt=\"\" class=\"wp-image-179\" width=\"633\" height=\"451\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-33.png\" alt=\"\" class=\"wp-image-180\" width=\"271\" height=\"256\"\/><\/figure>\n\n\n\n<p>As we are setting up our new ADFS, select &#8220;<strong>Create the first federation server in a federation server farm<\/strong>&#8221; &gt; Make sure there is &#8220;<strong>Domain Admin<\/strong>&#8221; connected to ADDS<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-34.png\" alt=\"\" class=\"wp-image-181\" width=\"486\" height=\"360\"\/><\/figure>\n\n\n\n<p><br>&nbsp;Select the&nbsp;<strong>SSL certificate<\/strong>&nbsp;we previously installed<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-35.png\" alt=\"\" class=\"wp-image-182\" width=\"537\" height=\"396\"\/><\/figure>\n\n\n\n<p>&nbsp;<strong><em>(Important)<\/em><\/strong>&nbsp;Choose the ADFS service account that we previously configured<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-36.png\" alt=\"\" class=\"wp-image-183\" width=\"535\" height=\"395\"\/><\/figure>\n\n\n\n<p>Choose the database depends on our environment (e.g. The default Windows Internal Database)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-37.png\" alt=\"\" class=\"wp-image-184\" width=\"532\" height=\"390\"\/><\/figure>\n\n\n\n<p>Review and Click&nbsp;<strong>Next<\/strong>&nbsp;&gt; Click&nbsp;<strong>Configure<\/strong>&nbsp;&gt; Finish the configuration<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-38.png\" alt=\"\" class=\"wp-image-185\" width=\"532\" height=\"392\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"4-create-the-dns-zone-records-for-the-active-directory-federation-service\">4. Create the DNS Zone &amp; Records for the Active Directory Federation Service<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"41-create-the-dns-zone\">4.1 Create the DNS Zone<\/h3>\n\n\n\n<p>Move to the Domain Contoller, open&nbsp;<strong>DNS Manager<\/strong>&nbsp;&gt; Expand &#8220;<strong>PDC<\/strong>&#8221; and create a &#8220;<strong>New Zone<\/strong>&#8221; under &#8220;<strong>Forward Lookup Zone<\/strong>&#8221; &gt; Keep default zone type as &#8220;<strong>Primary Zone<\/strong>&#8221; &gt; Enter the added Public Domain Name under&nbsp;<strong>Zone name<\/strong>&nbsp;&gt; Finish rest of configuration with default settings.&nbsp;<img decoding=\"async\" alt=\"\" src=\"https:\/\/blog.ruianding.com\/static\/images\/build_adfs\/adfs_16.gif\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-39.png\" alt=\"\" class=\"wp-image-186\" width=\"493\" height=\"353\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"42-create-the-a-record\">4.2 Create the A Record<\/h3>\n\n\n\n<p>Right click the Zone &gt;&nbsp;<strong>New Host (A or AAAA)<\/strong>&nbsp;&gt; Fill in the&nbsp;<strong>ADFS service name<\/strong>&nbsp;and&nbsp;<strong>ADFS server IPv4 address<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-40.png\" alt=\"\" class=\"wp-image-187\" width=\"410\" height=\"390\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-41.png\" alt=\"\" class=\"wp-image-188\" width=\"484\" height=\"339\"\/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"5-verify-the-active-directory-federation-service-fucntion\">5. Verify the Active Directory Federation Service Fucntion<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"51-verify-the-active-directory-federation-service-account\">5.1 Verify the Active Directory Federation Service Account<\/h3>\n\n\n\n<p>Open&nbsp;<strong>Services<\/strong>&nbsp;&gt; Double click&nbsp;<strong>Active Directory Federation Service<\/strong>&nbsp;&gt; Change to&nbsp;<strong>Log on<\/strong>&nbsp;tab &gt; And verify our service account<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-42.png\" alt=\"\" class=\"wp-image-189\" width=\"511\" height=\"375\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"52-test-the-idp-sign-in-dummy-page\">5.2 Test the IDP Sign-in Dummy Page<\/h3>\n\n\n\n<p>IDP test page is disabled by default. You will need to manually enable IDP page, you can use following PowerShell command to enable it:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Set-AdfsProperties -EnableIdpInitiatedSignonPage $true\n<\/code><\/pre>\n\n\n\n<p>After IDP page is enabled, please test sign-in from ADFS IDP page:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;&lt;youradfsservicename&gt;\/adfs\/ls\/idpinitiatedsignon.aspx\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-43.png\" alt=\"\" class=\"wp-image-190\" width=\"841\" height=\"422\"\/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>1. Install the SSL Certificate Prepare your new primary ADFS server. Join the primary ADFS server to your domain. Install your&nbsp;SSL certificate&nbsp;and import the certificate to the local computer&#8217;s certificates personal store.&nbsp; 2. Create the ADFS Service Account (Recommend)&nbsp;Move to Domain Controller, create a new ADFS Service Account, make sure this user account is added [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[42,10],"tags":[5],"class_list":["post-152","post","type-post","status-publish","format-standard","hentry","category-adfs","category-tutorial","tag-adfs"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"og:description\" content=\"1. Install the SSL Certificate Prepare your new primary ADFS server. Join the primary ADFS server to your domain. Install your&nbsp;SSL certificate&nbsp;and import the certificate to the local computer&#8217;s certificates personal store.&nbsp; 2. Create the ADFS Service Account (Recommend)&nbsp;Move to Domain Controller, create a new ADFS Service Account, make sure this user account is added [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\" \/>\n<meta property=\"og:site_name\" content=\"\u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-23T02:37:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-08-30T17:51:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\" \/>\n<meta name=\"author\" content=\"Ruian Ding\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ruian Ding\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\"},\"author\":{\"name\":\"Ruian Ding\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"headline\":\"Instruction of Deploy a New Primary ADFS Server\",\"datePublished\":\"2022-02-23T02:37:00+00:00\",\"dateModified\":\"2023-08-30T17:51:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\"},\"wordCount\":519,\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\",\"keywords\":[\"ADFS\"],\"articleSection\":[\"ADFS\",\"Tutorial\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\",\"name\":\"Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\",\"datePublished\":\"2022-02-23T02:37:00+00:00\",\"dateModified\":\"2023-08-30T17:51:13+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png\",\"width\":859,\"height\":226},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.ruianding.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Instruction of Deploy a New Primary ADFS Server\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\",\"url\":\"https:\/\/www.ruianding.com\/blog\/\",\"name\":\"Ruian's Tech Troubleshooting Toolbox\",\"description\":\"Debug the World.\",\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"alternateName\":\"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\",\"name\":\"Ruian Ding\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"width\":284,\"height\":284,\"caption\":\"Ruian Ding\"},\"logo\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.\",\"sameAs\":[\"https:\/\/www.ruianding.com\"],\"url\":\"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/","og_locale":"en_US","og_type":"article","og_title":"Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT","og_description":"1. Install the SSL Certificate Prepare your new primary ADFS server. Join the primary ADFS server to your domain. Install your&nbsp;SSL certificate&nbsp;and import the certificate to the local computer&#8217;s certificates personal store.&nbsp; 2. Create the ADFS Service Account (Recommend)&nbsp;Move to Domain Controller, create a new ADFS Service Account, make sure this user account is added [&hellip;]","og_url":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/","og_site_name":"\u6781\u7b80IT\uff5cSimpleIT","article_published_time":"2022-02-23T02:37:00+00:00","article_modified_time":"2023-08-30T17:51:13+00:00","og_image":[{"url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png","type":"","width":"","height":""}],"author":"Ruian Ding","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ruian Ding","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#article","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/"},"author":{"name":"Ruian Ding","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"headline":"Instruction of Deploy a New Primary ADFS Server","datePublished":"2022-02-23T02:37:00+00:00","dateModified":"2023-08-30T17:51:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/"},"wordCount":519,"publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png","keywords":["ADFS"],"articleSection":["ADFS","Tutorial"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/","url":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/","name":"Instruction of Deploy a New Primary ADFS Server - \u6781\u7b80IT\uff5cSimpleIT","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png","datePublished":"2022-02-23T02:37:00+00:00","dateModified":"2023-08-30T17:51:13+00:00","breadcrumb":{"@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#primaryimage","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/image-23.png","width":859,"height":226},{"@type":"BreadcrumbList","@id":"https:\/\/www.ruianding.com\/blog\/instruction-of-deploy-a-new-primary-adfs-server\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ruianding.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Instruction of Deploy a New Primary ADFS Server"}]},{"@type":"WebSite","@id":"https:\/\/www.ruianding.com\/blog\/#website","url":"https:\/\/www.ruianding.com\/blog\/","name":"Ruian's Tech Troubleshooting Toolbox","description":"Debug the World.","publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"alternateName":"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b","name":"Ruian Ding","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","width":284,"height":284,"caption":"Ruian Ding"},"logo":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/"},"description":"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.","sameAs":["https:\/\/www.ruianding.com"],"url":"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/comments?post=152"}],"version-history":[{"count":16,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/152\/revisions"}],"predecessor-version":[{"id":481,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/152\/revisions\/481"}],"wp:attachment":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/media?parent=152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/categories?post=152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/tags?post=152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}