https://azure.microsoft.com/en-gb/documentation/articles/active-directory-certificate-based-authenti...
Im attempting to configure CBA for my O365 tenant but im a tad confused regarding the prerequisites in the link above which state that a federation server must be configured.
In a cloud only/O365 deployment with no hybrid, and no requirement for on premise servers how can CBA be configured without the need for deploying ADFS/AD Federation? The Cloud identity for O365 is in Azure AD and therefore would be authenticated against Azure AD so why would a federation server be required unless of course im reading the article wrong?