nerdexam
Microsoft

70-649 · Question #212

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 has the Active Directory Federation Services (AD FS) role installed. You have…

The correct answer is B. Create a relying party trust. To create a relying party trust manually Click Start, point to Programs, point to Administrative Tools, and then click AD FS 2.0 Under AD FS 2.0\Trust Relationships, right-click Relying Party Trusts, and then click Add Relying Party Trust toopen the Add Relying Party Trust…

Configuring Active Directory Infrastructure

Question

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 has the Active Directory Federation Services (AD FS) role installed. You have an application named App1 that is configured to use Server1 for AD FS authentication. You deploy a new server named Server2. Server2 is configured as an AD FS 2.0 server. You need to ensure that App1 can use Server2 for authentication. What should you do on Server2?

Options

  • ACreate a relaying provider trust.
  • BCreate a relying party trust.
  • CAdd an attribute store.
  • DCreate a claims provider trust.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    74% (32)
  • C
    9% (4)
  • D
    14% (6)

Explanation

To create a relying party trust manually Click Start, point to Programs, point to Administrative Tools, and then click AD FS 2.0 Under AD FS 2.0\Trust Relationships, right-click Relying Party Trusts, and then click Add Relying Party Trust toopen the Add Relying Party Trust Wizard. On the Welcome page, click Start. On the Select Data Source page, click Enter data about the relying party manually, and then click On the Specify Display Name page type a name in Display name, under Notes type a description for thisrelying party trust, and then click Next. On the Choose Profile page, do one of the following: Click AD FS 2.0 profile, click Next, and then move to step 7. Click AD FS 1.0 and 1.1 profile, click Next, and then go to step 9. If you know you will require interoperability with older Active Directory Federation Services (AD FS) federation,as provided in Windows Server 2003 R2, click AD FS 1.0 and 1.1 profile. Otherwise, use the default AD FS 2.0profile. On the Configure Certificate page, click Browse to locate a certificate file, and then click Next. On the Configure URL page, do one or both of the following, click Next, and then go to step 10: Select the Enable support for the WS-Federation Passive protocol check box. Under Relying party WSFederationPassive protocol URL, type the URL for this relying party trust, and then click Select the Enable support for the SAML 2.0 WebSSO protocol check box. Under Relying party SAML 2.0 SSOservice URL, type the Security Assertion Markup Language (SAML) service endpoint URL for this relying partytrust, and then click Next. Click the Help button on this page for more information about which of these options apply to the needs of yourorganization. On the Configure URL page, under WS-Federation Passive URL, type the URL for this relying party trust, andthen click Next. On the Configure Identifiers page, specify one or more identifiers for this relying party, click Add to add them tothe list, and then click Next. On the Choose Issuance Authorization Rules page, select either Permit all users to access this relying party orDeny all users access to this relying party, and then click Next. On the Ready to Add Trust page, review the settings, and then click Next to save your relying party trustinformation. On the Finish page, click Close. This action automatically displays the Edit Claim Rules dialog box. For more information about how to proceed with adding claim rules for this relying party trust, see Additional references.

Topics

#AD FS#relying party trust#federation#authentication

Community Discussion

No community discussion yet for this question.

Full 70-649 Practice