COURSE OBJECTIVE:
ADF
After completing this course you should be able to:
• Design AD Federation Services infrastructure and identify the implementation requirements
• Deploy AD Federation Services to provide claims-aware authentication in a single organization
• Implement AD Federation Services high availability
• Deploy Web Application Proxy (previous: AD Federation server proxy) to securely publish web applications
• Deploy Device Registration Service to enable control of user devices
• Deploy Claims-enabled ACLs on File Servers
ADS
After you complete this course you will be able to:
• Deploy AD Federation Services to provide claims-aware authentication for multiple organizations.
• Implement AD Federation Services high availability and load balancing.
• Implement Claims filtering and processing, to secure multi-organization enabled application.
• Script and backup ADFS environment.
• Automate business partner setup procedure for ADFS.
• Configure Active Directory for ADFS
TARGET AUDIENCE:
Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.
COURSE PREREQUISITES:
Attendees should meet the following prerequisites:
• Good hands-on experience in administering a Windows infrastructure.
COURSE CONTENT:
ADF
Module 1
• Introduction
• What are Claims
• Dynamic Access Control
• LAB: Dynamic Access Control in 2016
• LAB (optional): DAC and Groups
Module 2
• What are current authentication mechanism in use
• LAB: Working with SPN
• Services Accounts – threats and gMS
• LAB: Enabling gMSA creation
• LAB (optional): Service credentials recovery (Windows)
• LAB (optional): IIS app pool password recovery
• PKI: Quick Overview of certification services – internal and 3rd party
• LAB: Requesting certificates
• LAB: Installing ADFS
Module 3
• Designing Modern Authentication
• ADFS Overview
• LAB (optional/demo): Installing ADFS Cluster
Module 4
• Working with ADFS – enable applications
• LAB: Install Simple Claims applications
• LAB (optional): Verify application config
• ADFS Basics – Rules and Rule flow
• LAB: Configuring Issuing rules
Module 5
• Thick applications, and working with multiple Relaying Parties
• LAB: Configuring Dynamics CRM
• LAB: Testing with Outlook
• LAB (optional): Testing with Windows 10
• Attribute Stores
• LAB: Configuring application Store
• LAB: Configuring authorization rules
• LAB (optional): Using groups in authorization rules
Module 6
• Web Application Proxy
• LAB: Installing WAP
• LAB: Configuring ADFS publishing
• LAB: Configuring Claims-aware application
• LAB (optional): Configure via application
• LAB (optional): Configure pass-through application
Module 7
• Customizing ADFS
• LAB: ADFS Customization
• Troubleshooting ADFS
• LAB: ADFS Troubleshooting
• Working with MFA
Module 8
• Enabling Device Registration Service
• LAB: Enabling Device Registration Service and working with claims
• Summary and review
• Exchange and claims (additional content)
• SharePoint and claims (additional content)
• Work Folders (additional content)
ADS
Module 1
• Working with external parties
• LAB: Installing ADFS in Forest/Domain trust environment
• LAB (optional): Install ADFS in 2003 domain-level environment
• LAB: Testing simple web application
• LAB: Testing thick application
Module 2
• Home Realm Discovery
• LAB: Hacking ADFS Claims
• LAB: Authorizing users
• Working with groups
• LAB: Adding additional claims
• LAB: Multiple roles and claims
• CpT and rules
• LAB: Per-CpT Rules
• LAB: MFA and CpT
Module 3
• Scripting ADFS
• LAB: Backup ADFS Config
• LAB: Export RP and CpT
• LAB: Unattended Installation
Module 4
• Working with clients
• LAB: Creating automatic client configuration scripts
• Working with IE Security Zones
• LAB: Creating GPO for IE zones
• LAB: Creating automated Claim Provided Trust configuration for clients
Module 5
• Load Balancing ADFS
• Setting up ADFS Farm
• LAB: Using IIS ARR to load-balance ADFS
• LAB (optional): Clustering IIS ARR
FOLLOW ON COURSES:
Not available. Please contact.