Active Directory Federation Services (AD FS) is the claim-based single sign-on (SSO) solution provided by Microsoft. It facilitates access to all integrated applications and systems with just your Active Directory (AD) credentials. To use AD FS, run it on Windows Server after installing the role in Server Manager. It is part of AD services.
The basic components of AD FS are:
AD FS plays the middleman between the target application or resource and AD to provide authenticated access to users.
Note: It is compulsory for the target application or resource to have Federated Trust relation with AD FS to enable SSO through AD FS.
The process of establishing a trust relationship and thus implementing SSO is not an easy one. It differs from one application to another, and the primitive UI of AD FS does not help. If you don't have a technician with deep knowledge about all the involved technologies, you will have to hire an expert exclusively for this, which adds to both security concerns and costs.
Although AD FS is a free tool, it requires the purchase of a Windows Server license. Also, the AD FS server and trust certificates need to be maintained by expert technicians, which further escalates costs. Apart from this, there is also the cost of maintaining and backing up the servers.
Given the improving technologies used by hackers to break into IT systems, AD FS needs added security layers. Also, the machine hosting this server role has to be well protected.
ADSelfService Plus is an integrated Active Directory single sign-on and self-service password management solution. It supports single sign-on for over a hundred pre-integrated enterprise applications and other custom applications.
ADSelfService Plus SSO configuration is user-friendly and quick. It can support SSO for any application that is SAML-based.
ADSelfService Plus can be installed in any Windows machine that is part of an AD domain and hosted on the internet. This reduces hardware and licensing costs phenomenally. Since it's a web app, it can be accessed anytime, anywhere without compromising security. The ADSelfService Plus web portal logon and integrated application logons can be configured to require advanced multi-factor authentication like biometrics and YubiKey authenticator.
The annual subscription cost of ADSelfService Plus is only a small fraction of the amount required to set up a full fledged SSO system using AD FS. We also offer a free version for small businesses with 50 users or less.
Other features ADSelfService Plus offers: