Can I run AD FS 2.0 on Windows 2012 R2

Kane 76 Reputation points
2020-07-31T20:29:34.407+00:00

Hello;

I am using Windows 2012 R2 Active Directory, because my cloud base application provider not support ADFS 3.0 (only ADFS 2.0), can I install ADFS 2.0 on a Windows 2012 R2 server.

Or, install a Windows Server 2008 R2 and run AD FS 2.0 on W2K8 R2 to integrate to Windows 2012 R2 Active Directory?

thanks!

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,222 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Andy David - MVP 145.1K Reputation points MVP
    2020-07-31T21:07:35.827+00:00

    ADFS 2.0 is not supported on 2012 R2.

    Note from this link:
    https://www.microsoft.com/en-gb/download/details.aspx?id=10909

    Supported Operating System
    Windows Server 2008 Datacenter, Windows Server 2008 Enterprise, Windows Server 2008 R2, Windows Server 2008 R2 Datacenter, Windows Server 2008 R2 Enterprise, Windows Server 2008 R2 Foundation, Windows Server 2008 R2 Standard, Windows Server 2008 Service Pack 2, Windows Server 2008 Standard, Windows Small Business Server 2008 Premium, Windows Small Business Server 2008 Standard

    As far as the domain controllers. This document states you can't run this is a forest with 2012 DCs and above. ( To be supported that is)
    AD DS
    For AD FS 2.0 to operate successfully, domain controllers in either the account partner organization or the resource partner organization must be running Windows Server 2003 SP1, Windows Server 2003 R2, or Windows Server 2008.

    When AD FS 2.0 is installed and configured on a domain-joined computer, the Active Directory user account store for that domain is made available as a selectable attribute store.

    Schema requirements
    AD FS 2.0 does not require schema changes or functional-level modifications to AD DS.

    Functional-level requirements
    Most AD FS 2.0 features do not require AD DS functional-level modifications to operate successfully. However, Windows Server 2008 domain functional level or higher is required for client certificate authentication to operate successfully if the certificate is explicitly mapped to a user's account in AD DS.

    https://video2.skills-academy.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff678034(v=ws.10)?redirectedfrom=MSDN#adds

    0 comments No comments