Using a local CP trust to support multiple Active Directory forests

Beginning with AD FS 2016, you have the option of using a local CP trust to integrate additional forests. The only thing that you need to know is that you will lose automatic home-realm discovery for internal users. You can only provide a custom solution to do this for you:

Using a local CP trust to support multiple Active Directory forests

You can configure the scenario with the following procedure:

  1. Set the credentials for the service account:
$credential = Get-Credential
  1. Change the HostName to your domain controller, and use Port 636 if configured for a secure connection: ...

Get Mastering Identity and Access Management with Microsoft Azure - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.