Active Directory Federation Services (AD FS) is a Microsoft server role offering federated authentication and single sign-on. It securely issues claims-based tokens to transfer identity between Active Directory and external applications. Administrators configure trust relationships, certificates and claim rules to adapt authentication flows to enterprise and…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Technical building block: can be automated, integrated, or operated.
Concrete cog in the system that works inside larger relationships.
AD FS is a Microsoft server role for federated authentication and single sign-on. It transfers identity as claims-based tokens between Active Directory and external applications.
Microsoft developed AD FS as a Windows Server component for federated identity across separate security and enterprise boundaries. The service establishes trust relationships between an accounts side and a resource side: after authentication in Active Directory Domain Services, a federation server issues a claims token that carries identity to partner applications without shared passwords or a shared user database.
Think of AD FS as a two-stage trust gate. On the left, Active Directory authenticates the user; AD FS packages the result into a signed claims token. On the right, the target application or a partner federation server verifies that token and accepts only the asserted claims. Certificates secure issuance, trust relationships connect the parties, and claims rules decide which attributes are released.
Two security domains accept the assertions issued by the other side.
A signed token carries identity attributes and other assertions to the receiving system.
The server authenticates users, issues tokens, and validates partner-issued tokens.
Rules control which identity data is read, transformed, or forwarded.
AD DS provides the local user authentication that AD FS builds on.
An XML-based standard for exchanging authentication and authorization information.
AD FS is useful when local directory services, partner portals, or older SAML and WS-Federation applications need SSO across organizational boundaries. It also helps when claims and signing must be tightly controlled. For new projects, Microsoft usually recommends Entra ID instead; AD FS therefore comes with more operational overhead from certificates, trust configuration, and server management.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.