Topologies for Azure AD Connect (AADConnect)

Let me cross-link this here, because I feel like this is one of the better, clearer articles of what you can and should not attempt to build with Azure AD Connect (AADConnect):

https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect-topologies/

It outlines nicely what scenarios and topologies are supported in the current version of AADConnect.

ADFS Capacity Planning Spreadsheet updated for Windows Server 2016

Good news!

The ADFS Capacity Planning Spreadsheet most of us are familiar with, has been updated to reflect Windows Server 2016 numbers and scaling. While the “old” spreadsheet was still “OK” for Windows Server 2012 R2, apparently there are a number of changes in Windows Server 2016′s ADFS that warranted for an updated version.

Nice!

The link to the spreadsheet is in the following TechNet article: “Planning for AD FS Capacity”, https://technet.microsoft.com/en-us/library/gg749899.aspx.

You find the link in the second table, “AD FS Capacity Planning Spreadsheet for Windows Server 2016 ” or clicking here: http://adfsdocs.blob.core.windows.net/adfs/ADFSCapacity2016.xlsx

Enjoy!

 

Upgrading the ADFS farm behavior level

[This blog posting was written with knowledge based on Windows Server 2016 TP4. Things may change in RTM.]

Some more investigations with ADFS in Windows Server 2016 TP4  – you have to start somewhere, right?

There are two ADFS servers that I mean to replace with two new ones on 2016 TP4, and then raise the farm behavior level. Easy enough – or so.

The plan:

  • Swap ADFS servers
  • Use the Test-ADFSFarmBehaviorLevelRaise CMDlet to test the procedure
  • Raise the ADFS Farm Behavior Level with Invoke-ADFSFarmBehaviorLevelRaise

The installation worked identical to installations with 2012 R2, when adding new nodes to an existing farm – in the end, there’s no difference between adding 2012 R2-based ADFS nodes to an existing farm or 2016-based nodes.

  • join to the domain
  • install the Service Communication cert on the new boxes
  • install ADFS role
  • add box to Load Balancer (probing will only activate it, when the service starts responding)
  • join to ADFS farm
  • Verify installation went good, event log is clean, WID replication worked

Read more »

Next Page »