Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8317113
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 8, 20262026-06-08T21:30:53+00:00 2026-06-08T21:30:53+00:00

I have the following Scenario: Three different Sharepoint Server: sp1.company.com; sp2.company.com… Internal Users using

  • 0

I have the following Scenario:

Three different Sharepoint Server: sp1.company.com; sp2.company.com…
Internal Users using Windows Authentication and external users using Forms Based Authentication (FBA).

When the external users change from one server to the other they have to login again. My goal is to have a Single Sign On (SSO) for all the SharePoint Server.

I thought maybe I can do this by using ADFS for the internal users and a customSts (ThinkTecture IdentityServer) for the external users.

Would this be possible? How do I setup the Sts servers ADFS and IdentityServer? Do I have to connect ADFS to IdentityServer over WS-Federation?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-08T21:30:55+00:00Added an answer on June 8, 2026 at 9:30 pm

    Yes, the architecture you are proposing is fine. You will have to stop using forms auth and windows auth on SharePoint and start using claims-based (SAML and WS-Fed) as the single login mechanism. The architectural pattern is: your applications trust a “federation hub” (that could be either ADFS or Windows Azure Active Directory). That server will have all the trust relationships with your identity providers and applications. In your case, what you have today, is a couple of SharePoint applications and two identity providers (one AD through ADFS and the other a custom database through something like Identity Server).

    Everything is connected through standard protocols and token formats. From SharePoint to the “federation hub” you will use WS-Federation and SAML 1.1 tokens. From the “federation hub” to ADFS you will use WS-Federation and SAML 1.1 or 2.0 tokens. From the “federation hub” to Identity Server it’s the same as ADFS. In the future if you want to plug something like Facebook, the “federation hub” needs to speak OAuth, but the SharePoint will still be using WS-Federation, so you don’t have to touch that piece.

    ADFS as a federation hub will give you support for WS-Federation and SAML protocol (but not OAuth). That might be good enough for you today. You might want to consider Windows Azure Active Directory (previously known as Windows Azure Access Control Service) which is a “federation hub” that is offered as a service from Microsoft (with a price tag of 2 USD per 100K login). Microsoft is currently more focused on WAAD other than ADFS. WAAD will give you support for OAuth, mobile scenarios, Office 365, etc. Not saying that ADFS is being retired or anything like that, simply my point of view of where the investments are being made.

    Putting things together requires some learning and time, so be prepared to hit some walls like certificate issues, miss-configurations, home realm discovery, claims transformation, SharePoint people picker, cookies, logout, etc.

    Here are some pointers:

    • Adding IdentityServer as a Claims Provider to ADFS is simple, you have to use the FederationMetadata endpoint provided by IdentityServer and add it as a Claims Provider in ADFS (Wizard or PowerShell).
    • Configuring SharePoint 2010 with ADFS
    • Setting up ADFS
    • Configuring SharePoint 2010 with Windows Azure AD to use Google and ADFS identities using Auth10 in 5 minutes. This last one belong to the product we are building that aims to simplify all these 🙂

    Matias

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

So lets say I have the following scenario. http://website.com:8080 and http://website.com:8080/demo Is there any
I am trying to understand isolation/locks in SQL Server. I have following scenario in
I have the following scenario where I have different kinds of sales algorithms to
Following scenario: We have to develop a lot of different forms and small or
I have the following scenario. We have a sharepoint 2010 web template to create
I have the following scenario: Two lists of different Types which happen to contain
I have the following scenario: I have a system full of users. There is
I have the following scenario (Asp.net 3.5, Windows Server 2008 R2, IIS7): User1 logs
I am developing a small app using jquery mobile. I have the following scenario
I have the following scenario: in activity A, when a user clicks a button,

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.