Should AD FS be installed on the same server that is also a DC? Is there a specific role that DC should have?
Hey! As far as I've seen, ADFS means that your local Active Directory authenticates and establishes a Token that is recognized by CRM. The alternative to that, is to rely on Azure for authentication.
Is AD FS the only option to permit off-prem users to work with D365 CE, or can a VPN product work?
Hey!
That's going to depend on the purpose of the installation: If it's a development environment or a Demo/testing purpose with just a few users, then having both things on the same server makes sense. You can read more on this approach on https://docs.microsoft.com/en-us/dynamics365/customerengagement/on-premises/deploy/deploy-and-configure-ad-fs. Please be aware that ADFS will install on the default site and that you'll need to configure a new website for the Dynamics 365 server.
However, for larger installations it's better to have these roles separated. On this link https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs there's some documentation (and specially a Topology diagram) that depicts that you should have one part on your corporate network (Domain controllers + ADFS) and on a DMZ a Web Application Proxy that will connect to the ADFS. Keep in mind that your Dynamics (WebServers + Database servers) will be on your corporate network.
Best regards
So is your recommendation that we install it on its OWN windows 2016 or 2019 server or can we install it on the same server as Dynamics CRM?
Hey!
This is old documentation but is valid still: docs.microsoft.com/.../cc778681(v=ws.10)
Because ADFS requires the installation of Internet Information Services (IIS), we strongly recommend that you not install any ADFS components on a domain controller in a production environment.
Hope it helps!
Stay up to date on forum activity by subscribing. You can also customize your in-app and email Notification settings across all subscriptions.
André Arnaud de Cal... 291,240 Super User 2024 Season 2
Martin Dráb 230,149 Most Valuable Professional
nmaenpaa 101,156