Sep 18 2017 08:59 PM
Sep 18 2017 08:59 PM
Newbee here, We have an O365 environment where we log in to O365 via AD FS. We have had many unplanned outage (not controlled by IT and many more scheduled) which has taken down power to our data center, which includes our AD FS server. How do others fail over to logging into the cloud instead of being down becasue of a power outage to your data center? We would like to by default use AD FS but fail over to cloud if AD FS is down.
Thoughts?
Sep 20 2017 01:27 AM
Hi Nathan,
You should have a high availability solution for AD FS with load balances AD FS and AD FS proxy servers. You can switch from single sign-on to password sync manually during an outage to give your users access to Office 365 applications. Or you can enable password sync as a backup option if single sign-on won't work.
You can find more information here: https://social.technet.microsoft.com/wiki/contents/articles/17857.dirsync-how-to-switch-from-single-...
https://www.edx.org/course/manage-office-365-identities-microsoft-cld243x
- Dominik
Sep 20 2017 03:37 AM
Hi Nathan,
I agree with Dominics comments.
More food for throught here https://gallery.technet.microsoft.com/ADFS-Design-Considerations-f30c0b95
Also, see discussion here on switching from federated to synchronized identity - especially if ADFS is offline
Sep 20 2017 07:39 AM
Better yet, as your organization doesnt seem to have the operational maturity to use AD FS, consider switching to Pass-trhough auth (https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-pass-thr...). It offers almost all benefits of AD FS, with greatly reduced on-premises footprint.
Sep 20 2017 08:32 AM
I agree. Pass Through Authentication worth considering too. Just be sure to check the supported / unsupported scenarios, especially if using legacy Office client applications (Office 2013 or earlier)
Sep 20 2017 08:41 AM
Sep 20 2017 08:41 AM
Thanks everyone for the responses. I am working with our Infrastructure Team on next steps.