Re: IIS Integrated Authentication with ADAM ?



Hi,

I don't believe you'll be able to use ADAM for this task (unless you write your own authentication module). The supplied Microsoft one only talks to AD.

What you could do is setup a second domain in your DMZ, and then configure a one-way trust with your existing Production domain. That way, users in your Production domain can access the website. You can put your external users in the DMZ domain, but they won't have any permissions/access back to the existing Prod domain.

Cheers
Ken

--
http://adopenstatic.com/blog

"JimmyMc" <james.mcmillan@xxxxxxxxx> wrote in message news:6dc94111-421d-430a-9c88-951fde92886e@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi

We currently have an Intranet site hosted on our IIS server that is
currently joined to the AD domain. Authentication is currently using
'Integrated Windows authentication'.

We have the need to open this up to external users and for obvious
reasons, want to move this IIS server to the DMZ and don't want it
joined to the domain.

I believe we need to utilise ADAM (i.e. Active Directory Application
Mode) but really don't know where to start. Can anyone help? Do we
need MIIS as well (sounds expensive from the basic research I've
done).

Is this an Infrastructure-only thing, or will we need development
resource as well?

Any starters-for-10 gratefully received..

Cheers, James

.



Relevant Pages

  • Re: AD Authentication in a DMZ (up) ?
    ... when we want that an application in a DMZ zone can use AD authentication ... request from DMZ to DCs? ... Thomas told me about ADAM, ADFS or a specific forest only for Applications ...
    (microsoft.public.windows.server.active_directory)
  • Advantages of ADAM ? Is it really secure ?
    ... I am actually searching for some informations about how to authenticate applications in my DMZ by using AD authentication. ... I have read that ADAM can do this by synchronizing user objects from AD to ADAM. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Deploy ADAM for authenticating
    ... ADAMSync to create bindProxy objects for your AD users in ADAM. ... ADAM server could be in the DMZ or inside, depending on which holes in the ... so that the Apps servers can ask for authentication from ...
    (microsoft.public.windows.server.active_directory)
  • Re: adam bind-redirect
    ... a third party doing authentication) then the proxy-redirect isnt an option. ... could benefit from bind redirect/User Proxy Object ... >> Our Adam will have a user store where we put custom user attributes. ... > Integrated authentication gives you a Windows security context ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM - SSO and provisioning considerations
    ... single credential store. ... > that app will launch our app, so it can pass the username or SID on the ... ADAM doesn't simplify your architecture from what I can tell in your posts. ... LDAP bind is not an authentication process. ...
    (microsoft.public.windows.server.active_directory)

Quantcast