Short for Active Directory Federation Services, a federation server hosted on-premises. Its older publishing role, Web Application Proxy, is a separate thing from Microsoft Entra application proxy.
Also called Active Directory Federation Services.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AD FS in context, with comparison tables and the common traps.
Terms in this definition
- Federation
An arrangement in which separate identity providers trust one another, letting people use the account from their home organisation to reach services in another domain. In a hybrid setup, Entra ID can pass sign-ins over to a federation service like AD FS.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Web Application Proxy
A legacy Windows Server role for publishing applications via AD FS; Microsoft Entra application proxy is a different thing.
- Microsoft Entra application proxy
Makes on-premises web applications reachable from outside using a connector that only makes outbound connections, so neither a VPN nor open inbound ports are required.
Related terms
- ADFS
Active Directory Federation Services, Microsoft's identity federation product. VCF Identity Broker accepts it as an outside IdP (over OIDC or SAML) so people can sign in to VCF.
- Certificate trust
With this Windows Hello for Business model, AD FS acts as registration authority while an enterprise PKI hands users their sign-in certificates. Its hybrid form depends on AD FS federation, and cloud Kerberos trust is now Microsoft's preferred choice.
- Microsoft Entra Connect Health
Watches the health of AD FS, AD DS and Entra Connect sync, reporting on it and sending alerts by email.
- Seamless single sign-on
A Microsoft Entra capability, included at no extra cost, that signs people in without a password prompt when they use domain-joined company devices on the company network. It pairs with password hash sync or pass-through authentication; AD FS is not supported.
- Seamless SSO
Entra feature that silently signs in domain-joined devices on the corporate network when using pass-through authentication or password hash sync, though not AD FS. No inbound ports are needed, but autologon.microsoftazuread-sso.com must be in the Local intranet zone.