Can one ADFS proxy associate with multiple ADFS server?

Grace Yin 111 Reputation points
2020-08-03T19:39:58.727+00:00

Hi,

I need to upgrade ADFS from windows 2008 R2 to Windows 2019. We have 10+ Relying party trust on the old ADFS. To minimize the impact, I plan to prepare a new ADFS so I can migrate them one by one to reduce the down time. Below are my questions.

  1. To direct the authentication to the new ADFS server, I need to register a new DNS name. Is it correct?
  2. We have one ADFS proxy on DMZ. Can one ADFS proxy to redirect the authentication to different ADFS server or do I have to create another ADFS proxy?

If this isn't a right way to migrate Relying party trust, please advise the best way.

Thanks in advance!

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,240 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pierre Audonnet - MSFT 10,181 Reputation points Microsoft Employee
    2020-08-03T20:07:25.317+00:00

    One WAP server can only use one ADFS farm.

    Is your ADFS on Windows Server 2008 R2 a farm deployment or a stand alone deployment?

    If that's a farm deployment, you can actually do a parallel run upgrade. It is the same process as in: https://video2.skills-academy.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn486815(v=ws.11)

    If that's a stand alone deployment, you will have do an actual migration. In that case you will need to bring a new infra with WAP and ADFS. And if the challenge is that you just have one public IP for the WAP, you could in theory publish the new WAP in a pass-through rule on the old WAP. DNS will have to follow, it will also break certificate based authentication (just in case you are using it).


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.