Reader small image

You're reading from  Azure Stack Hub Demystified

Product typeBook
Published inOct 2021
PublisherPackt
ISBN-139781801078603
Edition1st Edition
Right arrow
Author (1)
Richard Young
Richard Young
author image
Richard Young

Richard Young has been working in IT for over 35 years and is currently a principal consultant in the professional services division of Lenovo Global Technologies, covering EMEA. He works closely with customers to assist them in their journey to the cloud with a focus on hybrid cloud, especially focused on Microsoft Azure. His role covers both the strategy and deployment of hybrid cloud using Microsoft Azure Stack Hub and Azure Stack HCI. He holds both MCSE and MCSA certifications for Azure. He holds the MCPD certification for .NET development for the cloud, from back when he was a developer. He has been involved in multiple deployments of Azure Stack Hub throughout Europe over the last few years. He is a husband, father, and grandfather.
Read more about Richard Young

Right arrow

Configuring ADFS and Graph integration

By selecting ADFS as the identity provider, identities from an existing Active Directory forest are able to authenticate with resources within Azure Stack Hub. The existing Active Directory forest will need a deployment of ADFS instances to enable the creation of an ADFS federation trust.

Authentication is only one part of identity. To be able to manage RBAC in Azure Stack Hub, the Graph component must also be configured. The Graph component is used to look up the user account in the existing Active Directory forest when access to the resource is delegated. This is done using the LDAP protocol:

Figure 4.6 – The ADFS Graph topology

The existing ADFS is the account Security Token Service (STS), which sends the claims to Azure Stack Hub ADFS (that is, the resource STS). Automation in Azure Stack Hub creates the claims provider trust with the metadata endpoint for the existing ADFS.

A relying party trust must...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Azure Stack Hub Demystified
Published in: Oct 2021Publisher: PacktISBN-13: 9781801078603

Author (1)

author image
Richard Young

Richard Young has been working in IT for over 35 years and is currently a principal consultant in the professional services division of Lenovo Global Technologies, covering EMEA. He works closely with customers to assist them in their journey to the cloud with a focus on hybrid cloud, especially focused on Microsoft Azure. His role covers both the strategy and deployment of hybrid cloud using Microsoft Azure Stack Hub and Azure Stack HCI. He holds both MCSE and MCSA certifications for Azure. He holds the MCPD certification for .NET development for the cloud, from back when he was a developer. He has been involved in multiple deployments of Azure Stack Hub throughout Europe over the last few years. He is a husband, father, and grandfather.
Read more about Richard Young