Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7569247
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 30, 20262026-05-30T15:07:12+00:00 2026-05-30T15:07:12+00:00

We are using CRM 2011 w/ ADFS 2.0. Our users would like for one

  • 0

We are using CRM 2011 w/ ADFS 2.0. Our users would like for one url to be used for both internal and external users, but w/ the IFD Config in CRM 2011 this is not possible if we also want to use automatic login via the users current NTLM credentials. Is it possible to modify the ADFS signin page to detect if NTLM credentials are present and from the correct domain and if so automatically log the user in and redirect them back to the application with the correct ADFS tokens?

Is there enough API surface area and of the right types for us to modify the login page in this way or is the ticketing api closed off to the point that we couldn’t do this programatically?

Comment: We know that using UAG SP1 we can force a logon to ADFS to occur with NTLM credentials but our client is not planning on deploying UAG anytime soon.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-30T15:07:14+00:00Added an answer on May 30, 2026 at 3:07 pm

    Your question is not really clear to me, but there may be an answer in here somewhere anyway.

    As described on the Authentication Handler Overview page, AD FS 2.0 has a couple of authentication mechanisms. Which of these is chosen is determined based on what the “authentication request allows for”. This is not about the HTTP request from the user’s browser, but about the sign-in request coming from the relying party (CRM 2011 in your case). And there is no fallback: for each of the four handlers, “[I]f invoked, it does not pass the request on to the next handler.”

    So for example, if the WS-Federation sign-in request from CRM to AD FS (sent through the browser) says that integrated Windows authentication is fine, and if you have the Integrated handler at the top of your <localAuthenticationTypes> list, then IWA is always used for authenticating the user (so either NTLM or Kerberos, depending on browser/server capabilities). Whether the user is “internal” or “external” doesn’t matter.

    Do you want to use different authentication methods for different users? If so, then the only way to influence the chosen authentication method is at the source: in theory CRM could adapt its authentication request based on some information from the user or the user’s browser. If CRM is based on WIF, you might be able to do request manipulation in the WSFederationAuthenticationModule.RedirectingToIdentityProvider Event. Colleagues did WIF sign-in request manipulation successfully in SharePoint, using this mechanism.

    Do you always want silent sign-in (as opposed to getting a Windows credentials dialog from your browser)? In our experience, there are all kinds of reasons why an IWA negotiation can fail to convince the server that the client’s Windows credentials are actually valid, making the browser ask explicitly for credentials. The most obvious reason is that the browser cannot reach the server’s AD, but there are more.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

We are using Crm 2011 as our persistence layer and we noticed terrible performance.
We are a .NET LOB shop using MS CRM as our CRM platform. To
I'm trying to integrate Sugar CRM with one of my projects. I'm using Apache
In Microsoft Dynamics CRM 2011, I wrote one plug-in in C# for Account entity
I am querying data from CRM 2011 using FetchXML to build a report in
I am using FetchXML in SSRS 2008 to create a report from CRM 2011.
I have created one 'sub area' item 'Site Map' of CRM 2011. My requirement
I'm using crmsvcutil to generate early bound types. In the crm 4.0 days one
I have written a Linq to CRM query using CRM 2011 RC (v5) LINQ-to-CRM
I want to be able to enable/disable a CRM 2011 Organization using Deployment Service

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.