ADFS Mastery: From Zero to Hero
Build, break, migrate & secure federated identity — a complete hands‑on journey with Exchange OWA, M365, B2B, and cloud migration.
Welcome! 👋
Welcome to the ultimate hands‑on ADFS deep‑dive series!
Whether you’re an IT admin managing a Microsoft Active Directory environment, a cloud architect designing hybrid identity, or a security engineer hardening federated access — this series will take you from absolute beginner to advanced, production‑ready ADFS deployments.
Over the next several posts we will build, break, migrate, and optimise ADFS in a real internal lab, using Exchange Server OWA as our core relying party. Every lab step will be documented with clear explanations, commands, and screenshots.
Why This Series Exists
Active Directory Federation Services (ADFS) is still the backbone of countless enterprise identity architectures. It bridges on‑premises Active Directory with cloud apps, enables true Single Sign‑On, and gives you total control over authentication policies.
Yet many guides either stay too high‑level or assume you already know the inner workings. This series fills that gap by combining:
- Conceptual clarity – what, why, and when to use ADFS.
- Hands‑on lab walkthroughs – every step replicated in a safe VM environment.
- Real‑world scenarios – Exchange OWA, Microsoft 365, partner federation, M&A, and more.
- Migration & upgrade stories – from legacy versions to the latest ADFS, and even to cloud‑first alternatives.
By the end, you will not only be able to deploy ADFS but also troubleshoot, scale, and modernise it with confidence.
📌 Series Roadmap
The journey is split into ten carefully sequenced parts. Each part can be consumed independently, but they build on each other logically.
| # | Title | Focus | Level | Status |
|---|---|---|---|---|
| 1 | Series Introduction & Lab Blueprint (this post) | Overview, prerequisites, VM design, roadmap | Beginner | Live |
| 2 | ADFS Foundations: Concepts, Protocols & Terminology | SAML, WS‑Fed, OAuth, claims, relying parties | Beginner | Live |
| 3 | Lab Phase 1 – Domain, CA & ADFS Server | DC, AD CS, gMSA, first ADFS farm | Beginner | Live |
| 4 | Lab Phase 2 – Exchange OWA Federation | Integrate Exchange 2019 OWA, claims rules | Intermediate | Live |
| 5 | External Access with Web Application Proxy | Publish OWA securely, DMZ, MFA | Intermediate | Live |
| 6 | Microsoft 365 / Entra ID Federation | Connect on‑prem AD to M365 via ADFS | Advanced | Coming |
| 7 | B2B Federation with a Partner Org | Cross‑forest/org trust, claims‑based access | Advanced | Coming |
| 8 | Upgrading & Migrating ADFS | From ADFS 3.0/4.0 to 2022, farm migration | Advanced | Draft |
| 9 | Monitoring, Hardening & Disaster Recovery | Auditing, security, HA design, rapid restore | Advanced | Draft |
| 10 | Modern Migration: ADFS → Entra ID | Shift from federation to cloud‑only auth | Strategic | Draft |
Live Coming soon In draft
🧪 What You’ll Need to Follow Along
To replicate the hands‑on parts at home, you only need a decent PC/laptop and the following (all free/evaluation):
- Hyper‑V or VMware Workstation
- Windows Server 2022 Evaluation ISOs (3 VMs minimum)
- Exchange Server 2019 ISO (free 180‑day trial)
- Microsoft 365 trial tenant (for Part 6)
- Azure free account (for Part 10)
- A curious mind and a cup of coffee ☕
In each lab post, you’ll find real screenshots of every critical dialogue, certificate snap‑in, and configuration step. No blind copy‑paste – you’ll see exactly what to expect.
📝 How Each Blog Post Will Be Structured
For consistency and ease of learning, every post will follow a similar pattern:
- Objective & Real‑World Context – why you need this.
- Pre‑Lab Checklist – what must be in place.
- Step‑by‑Step Walkthrough – with commands and screenshot annotations.
- Deep Dive & Explanation – understanding the “magic”.
- Troubleshooting Common Pitfalls – because things will break.
- Next Steps – what we’ll build upon in the following post.
🏛️ ADFS Architecture & Core Components
Understanding the building blocks of ADFS is essential before diving into configuration. Here’s what makes up a federated identity solution:
- ADFS Server (IdP) – The heart of the federation. It issues security tokens based on Active Directory authentication.
- Web Application Proxy (WAP) – The reverse proxy that publishes ADFS and applications to the internet, enforcing pre‑authentication and MFA.
- AD FS Configuration Database – Stores farm settings, relying party trusts, claims rules, and certificate bindings. Can be Windows Internal Database (WID) or SQL Server.
- Service Account (gMSA) – The managed service account that runs the ADFS service, ensuring secure credential management.
- Token Signing & Encryption Certificates – SSL certificates for HTTPS, token signing (to prove token integrity), and token decryption (to protect claims).
We’ll deploy each component in the lab, and Part 3 will walk through the entire installation – from AD CS to the first ADFS farm.
🔑 Claims, Protocols & Authentication Flows
ADFS speaks multiple identity protocols. Here’s a quick reference to the key terms and flows you’ll encounter:
- SAML 2.0 – The Security Assertion Markup Language, used for web SSO and federation with third‑party apps.
- WS-Federation (WS-Fed) – The native protocol for ADFS, used by many Microsoft applications (e.g., Exchange, SharePoint).
- OAuth 2.0 & OIDC – Modern protocols for API access and identity, supported in ADFS 2016+.
- Claims – A set of name‑value pairs about a user (e.g., email, group, UPN). Claims rules transform incoming AD attributes into outgoing claims for the relying party.
- Relying Party Trust – The configuration that defines which applications trust your ADFS and what claims they expect.
- Authentication Flow – User → ADFS login → token issuance → application consumption. We’ll trace every step in the lab.
Part 2 is entirely dedicated to these concepts, with practical examples and diagrams.
🛡️ Security Best Practices & Hardening
ADFS is a critical security boundary. We’ll cover these essential practices in depth throughout the series:
- Certificate Lifecycle Management – Rotate token signing and encryption certificates before they expire to avoid outages.
- TLS 1.2+ and Strong Ciphers – Disable weak protocols and enforce modern security on the ADFS and WAP servers.
- Multi-Factor Authentication (MFA) – Integrate with Azure MFA or third‑party providers to enforce strong authentication.
- Extranet Lockout Policies – Protect against brute‑force attacks by locking out users after repeated failed attempts from external networks.
- Auditing & Monitoring – Enable Windows event logging, capture ADFS audit logs, and integrate with SIEM (e.g., Sentinel, Splunk).
- Least Privilege for Service Accounts – Use gMSA and restrict permissions to the AD FS service account.
Part 9 is entirely dedicated to hardening and disaster recovery, with actionable checklists.
🔧 Troubleshooting – Where Things Go Wrong
Even the best‑planned deployments hit snags. We’ll frequently address these common pain points:
- Certificate Errors – Mismatched subject names, expired certificates, or untrusted chains causing browser warnings.
- Token Issuance Failures – Misconfigured claim rules, missing attributes in AD, or clock skew between servers.
- WAP Connectivity Issues – Firewall rules, DNS resolution, or HTTP to HTTPS redirection problems.
- Authentication Loop – Browser cookies, federation metadata mismatches, or relying party trust misconfiguration.
- Performance Bottlenecks – SQL database latency, under‑provisioned VMs, or high token‑signing load.
- Upgrade Pitfalls – Database schema changes, service account permission loss, or certificate rollback after an upgrade.
Every lab part includes a dedicated troubleshooting section, so you learn to diagnose and fix issues like a pro.
✨ The “Aha!” Moments You’ll Hit
Watch your Exchange OWA redirect to ADFS, sign in once, and land in the mailbox – your first federated application!
Log in to Office 365 with your lab domain credentials without ever seeing a cloud login screen.
Upgrade an entire ADFS farm while users are still accessing apps – a true production skill.
Establish a cross‑organisation trust and share a federated app with a partner company in minutes.
🚀 Let’s Get Started
I’m excited to guide you through this journey. The series is designed to be read sequentially, but if you already know the basics, feel free to jump directly to the lab‑heavy parts.
👉 Next up: Part 2 – ADFS Foundations: Concepts, Protocols & Terminology
We’ll strip away the mystery behind SAML, claims, and tokens – no servers yet, just solid theory that makes everything else click.
Bookmark this series so you don’t miss a post.