how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO
admin
2023-03-20 04:01:36
0

1.首先登录Office 365:https://login.partner.microsoftonline.cn/

添加域:nos.hk.cn

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

在域名解析设置里添加TXT记录:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

这里先跳过添加用户的步骤。

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

在域名解析中添加以上的记录:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

其中:login 和 owa两条记录为了方便登录建议添加.

然后返回office 365 验证:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

显示已经添加成功!!

接下来设置AD同步:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

接下来

准备单一登录

 

环境:

AD DC  windows server 2008 R2    DC08.nos.hk.cn

AD FS  windows server 2012 R2    FS.nos.hk.cn

WebProxy windows server 2012 R2  WAP  (不能加域,放在DMZ区)

 

2.先决条件:https://docs.microsoft.com/zh-cn/azure/active-directory/connect/active-directory-aadconnect-prerequisites

1)Azure AD Connect:https://www.microsoft.com/en-us/download/details.aspx?id=47594

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

 

在DC08上安装 AzureADConnect.msi,Azure AD Connect 服务器必须安装 .NET Framework 4.5.1 或更高版本和 Microsoft PowerShell 3.0 或更高版本

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

安装 PS 3.0 /.net 4.5.1: Azure AD Connect 依赖于 Microsoft PowerShell 和 .NET Framework 4.5.1

https://www.microsoft.com/zh-cn/download/details.aspx?id=40855

Windows6.1-KB2819745-x64-MultiPkg:https://download.microsoft.com/download/3/D/6/3D61D262-8549-4769-A660-230B67E15B25/Windows6.1-KB2819745-x64-MultiPkg.msu

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

Microsoft .NET Framework 4.5.1 (Offline Installer): https://download.microsoft.com/download/1/6/7/167F0D79-9317-48AE-AEDB-17120579F8E2/NDP451-KB2858728-x86-x64-AllOS-ENU.exe

 

2)为 Azure AD Connect 启用 TLS 1.2:

  1. 如果使用 Windows Server 2008R2,请确保已启用 TLS 1.2。 Windows Server 2012 服务器及更高版本上应该已经启用了 TLS 1.2。 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client] "DisabledByDefault"=dword:00000000 "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server] "DisabledByDefault"=dword:00000000 "Enabled"=dword:00000001

 

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

出错了,

  • 如果目标服务器已加入域,请确保已启用“Windows 远程托管”

  • 在权限提升的 PSH 命令窗口中,使用命令 Enable-PSRemoting –force

  • 如果目标服务器是未加入域的 WAP 计算机,则需要满足一些额外的要求

  • 在目标计算机(WAP 计算机)上:

    确保 winrm(Windows 远程管理/WS-Management)服务正在通过“服务”管理单元运行

  • 在权限提升的 PSH 命令窗口中,使用命令 Enable-PSRemoting –force

    在运行向导的计算机上(如果目标计算机未加入域或者是不受信任的域):

  • 在权限提升的 PSH 命令窗口中,使用命令 :

Set-Item WSMan:\localhost\Client\TrustedHosts –Value -Force –Concatenate

在服务器AD FS上运行:Enable-PSRemoting –force

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

在WAP服务器上:

运行:Enable-PSRemoting –force

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

在DC08上运行:

Set-Item WSMan:\localhost\Client\TrustedHosts –Value WAP -Force –Concatenate

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

在WAP无法解析adfs.nos.hk.cn

在DC的DNS服务器和添加:

adfs和wap两条记录:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

和WAP服务器中host文件中添加:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

再添加WAP服务器成功:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

出错了:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO在AD FS服务器上打开:AD FS Management

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

添加:urn:federation:MicrosoftOnline

然后返回重试:

然后又出错了:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

 

在WAP手动上安装:WAP

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

得先导入证书:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

返回向导,就可以选择证书了:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO发布成功!!!

然后返回Azure AD Connect配置,点重试!

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

配置完成,下一步:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

配置外网DNS添加A记录:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

配置防火墙端口映射:

将外网IP的443 端口映射到DMZ区的WAP服务器的443

接下来验证一下ADFS是否OK?

To verify that a federation server is operational

  1. Open a browser window and in the address bar, type the federation server name, and then append it withfederationmetadata/2007-06/federationmetadata.xml to browse to the federation service metadata endpoint. For example,https://fs.contoso.com/federationmetadata/2007-06/federationmetadata.xml .

    If in your browser window you can see the federation server metadata without any SSL errors or warnings, your federation server is operational.

  2. You can also browse to the AD FS sign-in page (your federation service name appended with adfs/ls/idpinitiatedsignon.htm, for example, https://fs.contoso.com/adfs/ls/idpinitiatedsignon.htm). This displays the AD FS sign-in page where you can sign in with domain administrator credentials.

 

1.在IE访问:https://adfs.nos.hk.cn/federationmetadata/2007-06/federationmetadata.xml

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

2.访问:https://adfs.nos.hk.cn/adfs/ls/idpinitiatedsignon.htm

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

这说明ADFS配置成功。

接下来,我们配置加入域的客户端SSO

组策略设置IE受信任站点:

1、在计算机配置 - 管理模板 - Windows组件 - Internet控制面板中,有一项站点到区域分配列表:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

 

确保https://adfs.nos.hk.cn 加受信任的区域:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

确保IE设置高级中的“启用集成Windows 验证”选中:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

然后在IE中打开owa.nos.hk.cn登录 OWA:

自动跳转到adfs.nos.hk.cn

输入要登录的域账号和密码,并选中“记住我的凭据”:

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

how to deployment Office 365 AD FS SSO --布署 Office 365 AD FS SSO

以后就会自动登录不用在输入账号密码会自动登录 啦!

 

总结:Office 365 与AD FS 做SSO 主要注意有以下几点:

1.要有一张公网的证书,本次实验用的Symantec的免费证书,只支持一个域名,(之前的StarSSL证书不能用了)

2.用最新的Azure AD Connect  1.1.524.0 发布时间为:2017/5/17 最好是先安装好ADFS和WebProxy服务器,

不然会出现本次实验中的两次错误。

3.在做AD FS之前最好先做密码同步。

相关内容

热门资讯

学习新语·政绩观|“愚公”治山... 统筹:郭洁宇 朱旭东设计:殷哲伦新华社新媒体中心新华社出品
请问瓷砖外墙做防水多少钱 已有2条回答 回复者:小休维 瓷砖外墙防水涂料60元一平方。外墙透明防水涂料无色、透明、涂覆...
旧房翻新可以直接贴壁纸吗? 不可以的。首先墙纸就不能贴在乳胶漆墙面上,因为乳胶漆的工艺、质量等都会影响到墙皮的附着力,所以在乳胶...
怎样翻新厨房瓷砖墙面?墙面瓷砖... 厨房理不管是哪一种的瓷砖,都可以在旧瓷砖上贴新的瓷砖。个别严重起鼓或者破坏的瓷砖需要革除,革除后用马...
无缝瓷砖真的可以做到无缝吗 无缝瓷砖之间的缝隙确实比较小,但是想要做到真正的无缝应该是不太可能的,据说这种无缝瓷砖每个瓷砖之间的...
瓷砖可以翻新吗 瓷砖可以翻新。瓷砖翻新的方法有多种,比如可以重新进行上色,用瓷漆在瓷砖上重新进行涂色和美化,在施工过...
庄瑞雄称沈伯洋当市长2天就能解... 海峡导报综合报道 台民意机构民进党团干事长庄瑞雄日前称,鼠患是城市治理的问题,蒋万安必须要展现市长的...
双层大巴撞上限高架,车头嵌入架... 5月9日,广东湛江一双层大巴撞上限高架,造成车身和限高架受损,无人受伤。相关视频显示,一辆白色双层大...
五一票房冠军是惊悚片,“下沉市... 【文/新潮观鱼】今年“五一”档,有一个有意思的现象:一部看起来没有“爆款相”,演员和导演都没有很大票...
“几轮博弈后,特朗普发现:中国... 【文/观察者网 王一】当地时间5月9日,英国《金融时报》发长文分析称,在美国与中国围绕贸易、科技、地...