ADFS 2.0 and trust in a multi-forest environment


- have ~200 forests in corporate network. these user/account forests. e.g:  forest b, forest c, forest d , on.

- adfs 2.0 has been setup in forest , applications (mainly web-based) under forest a.

- 2-way transitive trust have been established between <> b, a<> c, <> d , on.

the challenge is:

1) these many forest-trusts cause  security risk ? user in forest b able see resources/accounts in forest c, d etc?

2) since in adfs claims rule, mapping e-mail-addresses (as active dir ldap attribute) nameid (outgoing claim type),  , email addresses known everyone. cause greater risk if person malicious intent, creates fake user in forest b (eg. b\alvin shane) given same email user forest c?

will fake user in forest b have same access/privileges user in forest c when email address matching?

hi,

if set forest between a <> b, a<>c, forest b not able see resources in forest c. forest trusts can created between 2 forests , cannot implicitly extended third forest.

and after forest trust has been established, users in domain able access resources when proper permissions assigned @ resources.  resources would not able accessed users in forest if have no permission assigned. 

here is blog talking accessing resources across forest:

accessing resources across forest , achieve single sign on (part1)

http://blogs.technet.com/b/mir/archive/2011/06/12/accessing-resources-across-forest-and-achieve-single-sign-on-part1.aspx

regarding adfs issue, we'd better seek in forum below:

http://social.msdn.microsoft.com/forums/en/geneva/

hope helps

best regards

michael


if have feedback on our support, please click here.


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client