SOLVED
Home

Using existing external ADFS infrastructure with New office 365 setup

%3CLINGO-SUB%20id%3D%22lingo-sub-170606%22%20slang%3D%22en-US%22%3EUsing%20existing%20external%20ADFS%20infrastructure%20with%20New%20office%20365%20setup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-170606%22%20slang%3D%22en-US%22%3EDear%20Team%20I%20am%20currently%20wotking%20with%20a%20customer%20on%20an%20office%20365%20migration.%201.%20Currently%20customer%20has%20an%20exising%20ADFS%202.0%20Infrastructure%20with%20endpoint%20say%20sts.domainA.com.%20domainA%20is%20only%20available%20externally%20and%20there%20is%20not%20internal%20DNS%20zone%20for%20domainA%20locally.%20Internal%20users%20that%20currently%20consume%20ADFS%20applications%20are%20re-directed%20to%20the%20external%20ADFS%20sts.domainA.com%20(no%20split-brain%20scenario%20for%20domainA.com)%202.%20All%20intenal%20users%20currenlt%20have%20their%20upn%20as%20domainB.local%20which%20we%20plan%20to%20change%2Fremove.%203.%20Due%20to%20new%20company%20branding%2C%20users%20emails%20address%20will%20be%20changing%20to%20user%40domainC.com.%20for%20best%20practice%2C%20we%20are%20planning%20to%20change%20user's%20upn%20in%20active%20directory%20to%20domainC.com%20to%20match%20their%20email%20addresses.%20My%20questions%20are%3A%201.%20Can%20i%20use%20the%20same%20adfs%20endpoint%20sts.domainA.com%20for%20federating%20the%20new%20domain%20domainC.com%20with%20office%20365%3F%202.%20Do%20i%20need%20an%20internal%20dns%20zone%20for%20domainA.com%3F%203.%20is%20it%20worth%20building%20a%20new%20ADFS%20infrastructure%20to%20match%20our%20new%20email%2Fupn%20i.e.%20sts.domainC.com%20Regards%20Victor%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-170606%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eadfs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-171622%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20existing%20external%20ADFS%20infrastructure%20with%20New%20office%20365%20setup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-171622%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20a%20requirement%2C%20but%20recommended.%20All%20your%20network%20traffic%20is%20going%20from%20external%20via%20proxy%20to%20your%20internal%20servers.%20This%20requires%20excellent%20latency%20and%20bandwidth%2C%20especially%20if%20a%20lot%20of%20your%20users%20login%20to%20ad%20fs%20from%20external%20via%20proxy.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESome%20companies%20have%20no%20split-brain%20dns%20as%20well%2C%20but%20they%20do%20some%20routing-tricks%20at%20the%20load%20balancer%20or%20proxy%20to%20re-route%20specific%20client%20ips%20directly%20to%20internal%20...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-171072%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20existing%20external%20ADFS%20infrastructure%20with%20New%20office%20365%20setup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-171072%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Dominic%20for%20the%20response.%20Is%20split-brain%20dns%20a%20requirement%20for%20exchange%20online%20hybrid%20deployment%3F%20Can%20you%20shed%20more%20light%20on%20the%20impact%20of%20not%20using%20split%20dns%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYhank%20you%20once%20again.%3C%2FP%3E%0A%3CP%3Evictor%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-170994%22%20slang%3D%22en-US%22%3ERe%3A%20Using%20existing%20external%20ADFS%20infrastructure%20with%20New%20office%20365%20setup%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-170994%22%20slang%3D%22en-US%22%3E%3CP%3E1.%20Yes.%20You%20can%20use%20sts.domainA.com%20for%20every%20federated%20domain.%3C%2FP%3E%0A%3CP%3E2.%20You%20should%20use%20split-brain%20DNS%2C%20this%20is%20a%20recommendation%20and%20best%20practices%20using%20AD%20FS%20and%20Office%20365%2C%20also%20if%20you%20are%20plan%20to%20use%20Exchange%20hybrid.%3C%2FP%3E%0A%3CP%3E3.%20No%2C%20you%20can%20use%20a%20single%20AD%20FS%20instance.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%2C%3C%2FP%3E%0A%3CP%3EDominik%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor
Dear Team I am currently wotking with a customer on an office 365 migration. 1. Currently customer has an exising ADFS 2.0 Infrastructure with endpoint say sts.domainA.com. domainA is only available externally and there is not internal DNS zone for domainA locally. Internal users that currently consume ADFS applications are re-directed to the external ADFS sts.domainA.com (no split-brain scenario for domainA.com) 2. All intenal users currenlt have their upn as domainB.local which we plan to change/remove. 3. Due to new company branding, users emails address will be changing to user@domainC.com. for best practice, we are planning to change user's upn in active directory to domainC.com to match their email addresses. My questions are: 1. Can i use the same adfs endpoint sts.domainA.com for federating the new domain domainC.com with office 365? 2. Do i need an internal dns zone for domainA.com? 3. is it worth building a new ADFS infrastructure to match our new email/upn i.e. sts.domainC.com Regards Victor
3 Replies
Highlighted

1. Yes. You can use sts.domainA.com for every federated domain.

2. You should use split-brain DNS, this is a recommendation and best practices using AD FS and Office 365, also if you are plan to use Exchange hybrid.

3. No, you can use a single AD FS instance.

 

Best,

Dominik

Highlighted
Solution

Thanks Dominic for the response. Is split-brain dns a requirement for exchange online hybrid deployment? Can you shed more light on the impact of not using split dns?

 

Yhank you once again.

victor

Highlighted

Not a requirement, but recommended. All your network traffic is going from external via proxy to your internal servers. This requires excellent latency and bandwidth, especially if a lot of your users login to ad fs from external via proxy.

 

Some companies have no split-brain dns as well, but they do some routing-tricks at the load balancer or proxy to re-route specific client ips directly to internal ...