ADFS Device Registration cross forest

Iron Contributor

Hi all,


is it possible to do device registration (and claims) across a forest trust?


it looks to me like it isnt possible due to the limitation of the Enable-AdfsDeviceRegistration -DeviceLocation command being "a domain within the same forest"


is there any other way to make this work cross forest? or is this a scenario for additional ADFS farms or moving to Azure AD registration and authentication?

(tagged ADFS 2016, its actually 2012 R2)




Hi Peter, afaik this is not possible to achieve with ADFS, you should look at moving the workload to Azure AD