<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Claims-Based Identity Blog</title><subtitle type="html">Federated Identity and the Identity Metasystem. 
Our forum is located at http://social.msdn.microsoft.com/Forums/en-US/Geneva/threads
</subtitle><id>http://blogs.msdn.com/b/card/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/" /><link rel="self" type="application/atom+xml" href="http://blogs.msdn.com/b/card/atom.aspx" /><generator uri="http://telligent.com" version="5.6.583.17018">Telligent Community 5.6.583.17018 (Build: 5.6.583.17018)</generator><updated>2010-04-27T16:55:00Z</updated><entry><title>Announcing July 2011 update to Access Control Service 2.0</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/07/25/announcing-july-2011-update-to-access-control-service-2-0.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/07/25/announcing-july-2011-update-to-access-control-service-2-0.aspx</id><published>2011-07-25T08:30:00Z</published><updated>2011-07-25T08:30:00Z</updated><content type="html">&lt;p&gt;Windows Azure AppFabric Access Control Service (ACS) 2.0 received a service update. All customers with ACS 2.0 namespaces automatically received this update, which primarily contained bug fixes in addition to a few new features and service changes:&lt;/p&gt;
&lt;h3&gt;Localization in eleven languages&lt;/h3&gt;
&lt;p&gt;The ACS management portal is now available in 11 languages. Newly-supported languages include Japanese, German, Traditional Chinese, Simplified Chinese, French, Italian, Spanish, Korean, Russian, and Brazilian Portuguese.&amp;nbsp; Users can choose their desired language from the language chooser in the upper-right corner of the portal.&lt;/p&gt;
&lt;h3&gt;Rules now support up to two input claims&lt;/h3&gt;
&lt;p&gt;The ACS 2.0 rules engine now supports a new type of rule that allows up to two input claims to be configured, instead of only one input claim. Rules with two input claims can be used to reduce the overall number of rules required to perform complex user authorization functions. For more information on rules with two input claims, see &lt;a href="http://msdn.microsoft.com/en-us/library/gg185923.aspx"&gt;http://msdn.microsoft.com/en-us/library/gg185923.aspx&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Encoding is now UTF-8 for all OAuth 2.0 responses&lt;/h3&gt;
&lt;p&gt;In the initial release of ACS 2.0, the character encoding set for all HTTP responses from the OAuth 2.0 endpoint was US-ASCII. In the July 2011 update, the character encoding of HTTP responses is now set to UTF-8 to support extended character sets.&lt;/p&gt;
&lt;h3&gt;Quotas Removed&lt;/h3&gt;
&lt;p&gt;The previous quotas on configuration data have been removed in this update. This includes removal of all limitations on the number of identity providers, relying party applications, rule groups, rules, service identities, claim types, delegation records, issuers, keys, and addresses that can be created in a given ACS namespace.&lt;/p&gt;
&lt;p&gt;Please use the following resources to learn more about this release:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/b/vbertocci/archive/2011/07/25/new-in-acs-portal-in-multiple-languages-a-new-rule-type-and-wave-bye-bye-to-quotas.aspx" target="_blank"&gt;Vittorio Bertocci's blog post&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/gg429787.aspx"&gt;Release Notes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=212360"&gt;MSDN Documentation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://acs.codeplex.com/"&gt;CodePlex Site&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For any questions or feedback please visit the &lt;a href="http://social.msdn.microsoft.com/Forums/en-US/windowsazuresecurity/threads"&gt;Security for the Windows Azure Platform&lt;/a&gt; forum.&lt;/p&gt;
&lt;p&gt;If you have not signed up for Windows Azure AppFabric and would like to start using these new capabilities, be sure to take advantage of our free trial offer. Just click on the image below and get started today!&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/en-us/appfabric/azure/purchase.aspx" target="_blank"&gt;&lt;img style="max-width: 550px;" border="0" alt="" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/5670.trial.png" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The Access Control Service Product Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10189457" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Announcing the WIF Extension for SAML 2.0 Protocol Community Technology Preview!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/05/16/announcing-the-wif-extension-for-saml-2-0-protocol-community-technology-preview.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/05/16/announcing-the-wif-extension-for-saml-2-0-protocol-community-technology-preview.aspx</id><published>2011-05-16T13:17:00Z</published><updated>2011-05-16T13:17:00Z</updated><content type="html">&lt;p&gt;It is our pleasure to announce the availability of the first CTP release of the WIF (Windows Identity Foundation) Extension for the &lt;a target="_blank" href="http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf"&gt;SAML 2.0 Protocol&lt;/a&gt; ! We heard your feedback about the necessity to have support for the SAML 2.0 protocol in WIF. Today, we announce an &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=219043"&gt;extension to WIF&lt;/a&gt; that delivers on that feedback.&lt;/p&gt;
&lt;p&gt;This WIF extension allows .NET developers to easily create claims-based &lt;a target="_blank" href="http://docs.oasis-open.org/security/saml/v2.0/saml-conformance-2.0-os.pdf"&gt;SP-Lite&lt;/a&gt; compliant Service Provider applications that use SAML 2.0 conformant identity providers such as AD FS 2.0.&lt;/p&gt;
&lt;p&gt;This CTP release includes a set of samples that illustrate how to use the extension. You can download the package that includes the WIF Extension for SAML 2.0 Protocol and samples from &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=219043"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Key features of this extension include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Service Provider initiated and Identity Provider initiated Web Single Sign-on (SSO) and Single Logout (SLO)&lt;/li&gt;
&lt;li&gt;Support for the Redirect, POST, and Artifact bindings&lt;/li&gt;
&lt;li&gt;All of the necessary components to create a &lt;a target="_blank" href="http://docs.oasis-open.org/security/saml/v2.0/saml-conformance-2.0-os.pdf"&gt;SP-lite&lt;/a&gt; compliant service provider application&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We&amp;rsquo;ll be looking for your questions, comments, and other feedback on the claims based identity forum &lt;a target="_blank" href="http://social.msdn.microsoft.com/Forums/en-US/Geneva/threads"&gt;here&lt;/a&gt;.&amp;nbsp; Watch this blog for future posts about the roadmap of this WIF extension.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Happy coding!&lt;/p&gt;
&lt;p&gt;The WIF Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10164876" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="samples" scheme="http://blogs.msdn.com/b/card/archive/tags/samples/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="WIF" scheme="http://blogs.msdn.com/b/card/archive/tags/WIF/" /></entry><entry><title>AD FS 2.0 Content Map is published</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/04/21/ad-fs-2-0-content-map-is-published.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/04/21/ad-fs-2-0-content-map-is-published.aspx</id><published>2011-04-21T17:56:00Z</published><updated>2011-04-21T17:56:00Z</updated><content type="html">&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;We have published an &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-content-map.aspx"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;AD FS 2.0 content map wiki page&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt; which is intended to act as a content&amp;nbsp;map for all members of the AD FS 2.0 community.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;This is an on-going effort. Members of the AD FS product team will monitor this article on a regular basis and will post new links as they become available on Microsoft.com. The following is the current TOC list of this article:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#learn"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Learn about AD FS 2.0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#research"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Research AD FS 2.0 Solutions&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#cloud"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Integration with Microsoft cloud products&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#onprem"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Integration with Microsoft on-premises products&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#nonMS"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Interoperability with non-Microsoft products &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#case"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Case studies &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#design"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Design and Deploy AD FS 2.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#manage"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Manage AD FS 2.0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#tshoot"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Troubleshooting AD FS 2.0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-survival-guide.aspx#additional"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;Additional AD FS 2.0 References&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA"&gt;&lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: Arial;"&gt;&lt;span style="line-height: 115%; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;"&gt;&lt;span style="font-family: arial,helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: times new roman,times;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: verdana,geneva;"&gt;We would like to enlist your help in adding useful links to this article in order to make hot AD FS 2.0 topics and solutions more discoverable to the overall community. If you know any useful AD FS 2.0 content that that is not listed in this&amp;nbsp;article or if you would like to have a hot AD FS 2.0 topic documented, please send your feedback to &lt;span style="line-height: 115%; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;"&gt;&lt;a href="mailto:adfs2wikifeedback@microsoft.com?subject=AD%20FS%202.0%20Content%20Map%20Feedback%20(http://social.technet.microsoft.com/wiki/contents/articles/ad-fs-2-0-content-map.aspx)"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;AD FS Product Team&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="line-height: 115%; color: #333333; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: ZH-CN; mso-bidi-language: AR-SA;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10156770" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Windows Azure AppFabric Access Control Service released!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/04/12/windows-azure-appfabric-access-control-service-available-now.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/04/12/windows-azure-appfabric-access-control-service-available-now.aspx</id><published>2011-04-12T22:00:00Z</published><updated>2011-04-12T22:00:00Z</updated><content type="html">&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;We are very happy to announce the general availability of&amp;nbsp;the April release of Windows Azure AppFabric Access Control Service!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;The new version of the Access Control Service includes all the great capabilities and enhancements that have been available in the Labs release of the service for several months. Now you can start using these capabilities in production.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;The new version of the service adds the following capabilities:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Federation provider and Security Token Service&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Out of box federation with Active Directory Federation Services 2.0, Windows Live ID, Google, Yahoo, Facebook&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;New authorization scenarios&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Delegation using OAuth 2.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Improved developer experience&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;New web-based management portal&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Fully programmatic management using OData&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraph"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Works with Windows Identity Foundation &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b&gt;Additional protocol support&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoNormal" style="margin: 0in 0in 10pt; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;WS-Federation, WS-Trust, OpenID 2.0, OAuth 2.0 (Draft 13)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;This release represents a major enhancement to the previous version of Access Control Service, enabling new web application and web service federation scenarios. What&amp;rsquo;s more, we are excited to announce that Access Control Service will be offered &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;at no charge during the promotion period ending January 1, 2012!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Please use the following resources to learn more about this release:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpFirst"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/gg602420.aspx"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span lang="EN-US" style="mso-ansi-language: EN-US;"&gt;Detailed FAQ&lt;/span&gt;s&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpMiddle"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=212360"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;MSDN Documentation&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: #1f497d;"&gt; &lt;/span&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div class="MsoListParagraphCxSpLast"&gt;&lt;a href="http://acs.codeplex.com/"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;CodePlex Site&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #1f497d;"&gt; &lt;/span&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If you have any questions, be sure to visit the &lt;/span&gt;&lt;/span&gt;&lt;a href="http://social.msdn.microsoft.com/Forums/en-US/windowsazuresecurity/threads"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Security for the Windows Azure Platform&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-ansi-language: EN;"&gt; &lt;span lang="EN"&gt;section of the MSDN forums.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-ansi-language: EN;"&gt;&lt;span lang="EN"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;If you have not signed up for Windows Azure AppFabric and would like to start using these great new capabilities, be sure to take advantage of our free trial offer. Just click on the image below and get started today!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;o:p&gt;&lt;a href="http://www.microsoft.com/en-us/appfabric/azure/purchase.aspx"&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/5670.trial.png" border="0" /&gt;&lt;/a&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;a href="http://www.microsoft.com/en-us/appfabric/azure/purchase.aspx" title="&amp;quot;Windows Azure AppFabric Free Trial Offer&amp;quot; t "&gt;&lt;span style="color: windowtext; text-decoration: none; text-underline: none; mso-no-proof: yes;"&gt;&lt;v:shapetype coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f" id="_x0000_t75"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;v:fill o:detectmouseclick="t"&gt;&lt;/v:fill&gt;&lt;v:imagedata src="file:///C:\Users\asmalser\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png" o:title="0537.AppFabric-Free-Offer"&gt;&lt;/v:imagedata&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;The Access Control Service Product Team&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10152890" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>AD FS 2.0 Step-by-Step Guide: Federation with IBM Tivoli Federated Identity Manager</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/04/04/ad-fs-2-0-step-by-step-guide-federation-with-ibm-tivoli-federated-identity-manager.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/04/04/ad-fs-2-0-step-by-step-guide-federation-with-ibm-tivoli-federated-identity-manager.aspx</id><published>2011-04-04T20:48:23Z</published><updated>2011-04-04T20:48:23Z</updated><content type="html">&lt;p style="line-height: 13.5pt; background: white;"&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi;"&gt;We have published a step-by-step guide on how to configure AD FS 2.0 and IBM Tivoli Federated Identity Manager to federate using the SAML 2.0 protocol. You can view the guide as a &lt;/span&gt;&lt;span style="font-family: 'Trebuchet MS','sans-serif'; color: #555555; font-size: 10pt;"&gt;&lt;a href="http://technet.microsoft.com/en-us/library/gg749921(WS.10).aspx"&gt;&lt;span style="color: #0066dd;"&gt;web page&lt;/span&gt;&lt;/a&gt; and soon also in Word and PDF formats&lt;/span&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi;"&gt;. This is the fifth in a series of these guides; the guides are also available on the &lt;a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx"&gt;&lt;span style="color: blue;"&gt;AD FS 2.0 Step-by-Step and How-To Guides&lt;/span&gt;&lt;/a&gt; page.&lt;/span&gt;&lt;span lang="EN" style="font-family: 'Segoe UI','sans-serif'; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10149718" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /></entry><entry><title>Beyond Windows CardSpace</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/02/15/beyond-windows-cardspace.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/02/15/beyond-windows-cardspace.aspx</id><published>2011-02-15T15:59:00Z</published><updated>2011-02-15T15:59:00Z</updated><content type="html">&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;For several years Microsoft has advocated the claims based identity model for more secure access and use of online applications and services. With enhancements to our existing platform, such as &lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/windowsserver/dd448613.aspx"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Active Directory Federation Services 2.0&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #1f497d; mso-bidi-font-size: 10.0pt;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;and&lt;span style="color: #1f497d;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/evalcenter/dd440951.aspx"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Windows Identity Foundation&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;, we&amp;rsquo;ve made progress in that initiative.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Claims-based identity is used widely inside Microsoft and is now part of many Microsoft products, such as SharePoint, Office 365, Dynamics CRM, and Windows Azure. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Microsoft has been a leading participant in the identity community and an active contributor to emerging identity standards. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;We have increased our commitment to standardization activities and added support into our products for the SAML 2.0, OpenID 2.0, OAuth WRAP and OAuth 2.0 protocols.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;There is one component of our identity portfolio where we have recently decided to make a change.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Windows CardSpace was initially released and developed before the pervasive use of online identities across multiple services. Perhaps more importantly, we released the user component before we and others had delivered the tools for developers and administrators to easily create claims-ready services. The identity landscape has changed with the evolution of tools and cloud services.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Based on the feedback we have received from partners and beta participants, we have decided not to ship Windows CardSpace 2.0.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Claims-based identity remains a central concept for Microsoft&amp;rsquo;s identity strategy, and its role in our overall strategy continues to grow. Furthermore, we are not abandoning the idea of a user agent for exchanging claims. As part of our work on claims-based identity we are releasing a new technology preview of U-Prove. This &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/u-prove"&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;release of U-Prove&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #1f497d; mso-bidi-font-size: 10.0pt;"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-size: 10.0pt;"&gt;will take the form of a user agent that takes account of cloud computing realities and takes advantage of the high-end security and privacy capabilities within the extended U-Prove&lt;/span&gt; &lt;span style="mso-bidi-font-size: 10.0pt;"&gt;cryptographic technology. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10129628" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="CardSpace" scheme="http://blogs.msdn.com/b/card/archive/tags/CardSpace/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /><category term="U-Prove" scheme="http://blogs.msdn.com/b/card/archive/tags/U_2D00_Prove/" /><category term="Windows Identity Foundation" scheme="http://blogs.msdn.com/b/card/archive/tags/Windows+Identity+Foundation/" /></entry><entry><title>Single Sign-On to Windows Azure using WIF and ADFS whitepaper now available</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2011/01/05/single-sign-on-to-windows-azure-using-wif-and-adfs-whitepaper-released.aspx" /><id>http://blogs.msdn.com/b/card/archive/2011/01/05/single-sign-on-to-windows-azure-using-wif-and-adfs-whitepaper-released.aspx</id><published>2011-01-05T16:54:00Z</published><updated>2011-01-05T16:54:00Z</updated><content type="html">&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;We have published a whitepaper on how to enable Single Sign-On to Windows Azure using WIF and ADFS. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Here is the abstract:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;This paper contains step-by-step instructions for using Windows&amp;reg; Identity Foundation, Windows Azure, and Active Directory Federation Services (AD FS) 2.0 for achieving SSO across web applications that are deployed both on premises and in the cloud. Previous knowledge of these products is not required for completing the proof of concept (POC) configuration. This document is meant to be an introductory document, and it ties together examples from each component into a single, end-to-end example. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Download it &lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=1296e52c-d869-4f73-a112-8a37314a1632"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10112079" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /><category term="Azure" scheme="http://blogs.msdn.com/b/card/archive/tags/Azure/" /><category term="WIF" scheme="http://blogs.msdn.com/b/card/archive/tags/WIF/" /><category term="Windows Identity Foundation" scheme="http://blogs.msdn.com/b/card/archive/tags/Windows+Identity+Foundation/" /></entry><entry><title>Protecting and consuming REST based resources with ACS, WIF, and the OAuth 2.0 protocol</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/11/29/protecting-and-consuming-rest-based-resources-with-acs-wif-and-the-oauth-2-0-protocol.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/11/29/protecting-and-consuming-rest-based-resources-with-acs-wif-and-the-oauth-2-0-protocol.aspx</id><published>2010-11-29T23:45:04Z</published><updated>2010-11-29T23:45:04Z</updated><content type="html">&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0pt 0pt 10pt; font-family: Calibri; font-size: 11pt;"&gt;ACS (Azure Access Control Service) recently added support for the &lt;a href="http://tools.ietf.org/html/draft-ietf-oauth-v2-10"&gt;OAuth 2.0 protocol&lt;/a&gt;. If you haven&amp;rsquo;t heard of it, OAuth is an open protocol that is being developed by members of the identity community to solve the problem of allowing 3rd party applications to access their data without providing their passwords. In order to show how this can be done with WIF and ACS, we have posted a sample &lt;a href="https://connect.microsoft.com/site1168/Downloads"&gt;on Microsoft Connect&lt;/a&gt; that shows an end-to-end scenario. &lt;/p&gt;
&lt;p style="margin: 0pt 0pt 10pt; font-family: Calibri; font-size: 11pt;"&gt;The scenario in the sample is meant to be as simple as possible to show the power of the OAuth protocol to enable web sites to access resource on behalf of a user without the user providing his or her credentials to that site. In our scenario, Contoso has a web service that exposes customer information that needs to be protected. Fabrikam has a web site and wants users to be able to view their Contoso data directly on it. The user doesn&amp;rsquo;t have to log in to the Fabrikam site, but gets redirected to a Contoso specific site in order to login and give consent to access data on their behalf. &lt;/p&gt;
&lt;p style="margin: 0pt 0pt 10pt; font-family: Calibri; font-size: 11pt;"&gt;The Contoso web service requires OAuth access tokens from ACS to be attached to incoming requests. The necessary protocol flow for the Fabrikam web site (in OAuth terms &amp;ndash; the web server client), including redirecting the user to login and give consent, requesting access tokens from ACS, and attaching the token to outgoing requests to the service is taken care of under the covers. The sample contains a walkthrough that describes the components in more detail.&lt;/p&gt;
&lt;p style="margin: 0pt 0pt 10pt; font-family: Calibri; font-size: 11pt;"&gt;Try it out &lt;a href="https://connect.microsoft.com/site1168/Downloads"&gt;here&lt;/a&gt;, and tell us what you think!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10098039" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="samples" scheme="http://blogs.msdn.com/b/card/archive/tags/samples/" /><category term=".NET 4.0" scheme="http://blogs.msdn.com/b/card/archive/tags/-NET+4-0/" /><category term="Azure" scheme="http://blogs.msdn.com/b/card/archive/tags/Azure/" /><category term="WIF" scheme="http://blogs.msdn.com/b/card/archive/tags/WIF/" /><category term="OAuth" scheme="http://blogs.msdn.com/b/card/archive/tags/OAuth/" /><category term="ACS" scheme="http://blogs.msdn.com/b/card/archive/tags/ACS/" /></entry><entry><title>AD FS 2.0 Step-by-Step Guide: Federation with Ping Identity PingFederate</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/11/23/ad-fs-2-0-step-by-step-guide-federation-with-ping-identity-pingfederate.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/11/23/ad-fs-2-0-step-by-step-guide-federation-with-ping-identity-pingfederate.aspx</id><published>2010-11-23T01:06:00Z</published><updated>2010-11-23T01:06:00Z</updated><content type="html">&lt;p&gt;&lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi;"&gt;We have published a step-by-step guide on how to configure AD FS 2.0 and Ping Identity PingFederate to federate using the SAML 2.0 protocol.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;You can view the guide in &lt;a href="http://go.microsoft.com/fwlink/?LinkID=206832"&gt;docx, doc, or PDF formats&lt;/a&gt; and also as a &lt;a href="http://technet.microsoft.com/en-us/library/adfs2-federation-with-ping-identity-ping-federate(WS.10).aspx" title="web page"&gt;web page&lt;/a&gt;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;This is the fourth in a series of these guides; the guides are also available on the &lt;a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx"&gt;&lt;span style="color: #0000ff;"&gt;AD FS 2.0 Step-by-Step and How-To Guides&lt;/span&gt;&lt;/a&gt; page.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Special thanks to Ping Identity for sponsoring this guide.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10095200" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /></entry><entry><title>Access Control for Windows Phone 7 Apps</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/11/06/access-control-for-windows-phone-7-apps.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/11/06/access-control-for-windows-phone-7-apps.aspx</id><published>2010-11-06T05:17:00Z</published><updated>2010-11-06T05:17:00Z</updated><content type="html">&lt;p&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/3755.blog.bmp" border="0" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;With the &lt;/span&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;U.S. release of&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;Windows Phone 7 around the corner, I&amp;rsquo;m excited to share a &lt;a href="http://acs.codeplex.com/wikipage?title=ACS%20Windows%20Phone%20Sample&amp;amp;referringTitle=Samples"&gt;sample&lt;/a&gt; that shows some of our early thinking around how &lt;a href="https://portal.appfabriclabs.com/Default.aspx"&gt;ACS&lt;/a&gt; in LABS can be used to enable sign in to web services&amp;hellip; from the phone apps.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;This makes it simple to write REST services, for Windows Phone 7 Silverlight applications, that can be used millions of users, including those at Live ID, Facebook, Google, Yahoo and AD FS accounts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;To see it in action, check out &lt;a href="http://bit.ly/cNdEcM"&gt;Vittorio&amp;rsquo;s PDC&lt;/a&gt; talk. The sample appears in the last few minutes, but I recommend watching the full talk.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;As an early sample of how mobile apps may be supported, your feedback is very valuable. &lt;a href="http://acs.codeplex.com/wikipage?title=ACS%20Windows%20Phone%20Sample&amp;amp;referringTitle=Samples"&gt;Download it&lt;/a&gt; and try it out!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #595959; font-size: 11pt;"&gt;Caleb Baker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #595959; font-size: 11pt;"&gt;Program Manager - Access Control Services&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10087032" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="wp7 ACS phone" scheme="http://blogs.msdn.com/b/card/archive/tags/wp7+ACS+phone/" /></entry><entry><title>AD FS 2.0 Step-by-Step Guide: Federation with Shibboleth 2 and the InCommon Federation</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/10/22/ad-fs-2-0-step-by-step-guide-federation-with-shibboleth-2-and-the-incommon-federation.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/10/22/ad-fs-2-0-step-by-step-guide-federation-with-shibboleth-2-and-the-incommon-federation.aspx</id><published>2010-10-22T02:43:00Z</published><updated>2010-10-22T02:43:00Z</updated><content type="html">&lt;p&gt;&lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;We have published a step-by-step guide on how to configure AD FS 2.0 and &lt;a href="http://shibboleth.internet2.edu/"&gt;Shibboleth&lt;/a&gt; to federate using the SAML 2.0 protocol.&amp;nbsp; There is also an appendix on federating with the &lt;a href="http://www.incommonfederation.org/"&gt;InCommon Federation&lt;/a&gt;.&amp;nbsp; You can view the guide in &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e4770f44-93a1-4641-8add-32e076f0aae7"&gt;docx format&lt;/a&gt; and as a &lt;span style="line-height: 115%; font-family: 'Calibri','sans-serif'; color: #333333; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=204784"&gt;web page&lt;/a&gt;&lt;/span&gt;.&amp;nbsp; This is the third in a series of these guides; the guides are also available on the &lt;a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx"&gt;AD FS 2.0 Step-by-Step and How-To Guides&lt;/a&gt; page.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10079199" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /></entry><entry><title>“Programming Windows Identity Foundation” is available!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/09/17/programming-windows-identity-foundation-is-available.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/09/17/programming-windows-identity-foundation-is-available.aspx</id><published>2010-09-17T16:09:00Z</published><updated>2010-09-17T16:09:00Z</updated><content type="html">&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;a href="http://oreilly.com/catalog/9780735627185"&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/7181.book.gif" align="left" border="0" /&gt;&lt;/a&gt;My name is Peter Kron and I&amp;rsquo;m a Principal Software Developer on the Windows Identity Foundation team. Over the last year it has been my pleasure to work with Vittorio Bertocci as the technical reviewer for his latest book, &lt;b style="mso-bidi-font-weight: normal;"&gt;Programming Windows Identity Foundation. &lt;/b&gt;Many of you will recognize Vittorio from his engaging sessions at PDC, TechEd, IDWorld and other conferences, or follow his popular blog, &lt;/span&gt;&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-bidi-font-size: 10.0pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-fareast; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;a href="http://blogs.msdn.com/b/vbertocci/"&gt;&lt;span lang="EN" style="font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;&lt;span style="color: #0066dd;"&gt;Vibro.NET&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;. He has also authored or co-authored other books for Microsoft Press.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;/span&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;Vittorio is a Senior Architect Evangelist with Microsoft and over the past five years has been active (and if you know Vittorio, you know that is &lt;i style="mso-bidi-font-style: normal;"&gt;very&lt;/i&gt; active) in helping customers develop SOA based on WCF and, most recently, Identity. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;His experience working through real-world scenarios with numerous developers makes him an ideal choice to write this book. He knows the issues they have faced and how Microsoft technologies like WCF and WIF can be brought to bear on them. In this book, Vittorio takes the reader through basic scenarios and explains the power of claims. He shows how to quickly create a simple claims-based application using WIF. Beyond that, he systematically explores the extensibility points of WIF and how to use them to handle more sophisticated scenarios such as Single Sign-on, delegation, and claims transformation, among others.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;Vittorio goes on to detail the major classes and methods used by WIF in both passive browser-based applications and active WCF services. Finally he explores using WIF as your applications move to cloud-based Windows Azure roles and RIA futures.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;&lt;/span&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;I think you&amp;rsquo;ll find this book a valuable tool for learning how to build claims-based web applications and services. Or you will keep a copy handy for reference, as I do. The book is available now from &lt;/span&gt;&lt;a href="http://oreilly.com/catalog/9780735627185/"&gt;&lt;span lang="EN" style="font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;&lt;span style="color: #0066dd;"&gt;Microsoft Press&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="color: black; font-size: 12pt; mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ansi-language: EN;"&gt;, and all of the sample code described in the book is available for download.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;&lt;span lang="EN" style="font-family: 'Calibri','sans-serif'; color: black; font-size: 12pt; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;All of us on the WIF team are happy to see this in print (and e-book)!&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10064059" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Demonstrating federation interop with CA, IBM, and Sun products</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/09/03/demonstrating-federation-interop-with-ca-ibm-and-sun-products.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/09/03/demonstrating-federation-interop-with-ca-ibm-and-sun-products.aspx</id><published>2010-09-03T20:40:24Z</published><updated>2010-09-03T20:40:24Z</updated><content type="html">&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;Microsoft&amp;rsquo;s Patterns &amp;amp; Practices group recently wrote about three labs demonstrating federation interoperability between WIF and AD FS 2.0 and three other vendor products &amp;ndash; specifically, CA SiteMinder 12.0, IBM Tivoli Federated Identity Manager 6.2, and Sun OpenSSO 8.0.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;First, the team took the samples from the &lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ff423674.aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Claims Identity Guide&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt; and deployed them in a lab.&amp;nbsp; They then configured the lab to use IBM, Computer Associates &amp;amp; Sun identity providers.&amp;nbsp; Finally, they captured videos of demos for each configuration.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;You can read about each of the labs here:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/b/eugeniop/archive/2010/07/01/identity-federation-interoperability-wif-adfs-ca-siteminder.aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Identity Federation Interoperability &amp;ndash; WIF + ADFS + CA SiteMinder&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/b/eugeniop/archive/2010/06/30/identity-federation-interoperability-wif-adfs-ibm-tivoli-federated-identity-manager.aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Identity Federation Interoperability &amp;ndash; WIF + ADFS + IBM Tivoli Federated Identity Manager&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-size: small;"&gt;&amp;middot;&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/b/eugeniop/archive/2010/06/30/identity-federation-interoperability-wif-adfs-sun-s-opensso.aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Identity Federation Interoperability &amp;ndash; WIF + ADFS + Sun&amp;rsquo;s OpenSSO&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10057913" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="samples" scheme="http://blogs.msdn.com/b/card/archive/tags/samples/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /><category term="WIF" scheme="http://blogs.msdn.com/b/card/archive/tags/WIF/" /></entry><entry><title>Announcing Active Directory Federation Services 2.0 Management Pack for Microsoft System Center Operations Manager 2007</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/08/06/announcing-active-directory-federation-services-2-0-management-pack-for-microsoft-system-center-operations-manager-2007.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/08/06/announcing-active-directory-federation-services-2-0-management-pack-for-microsoft-system-center-operations-manager-2007.aspx</id><published>2010-08-06T20:37:00Z</published><updated>2010-08-06T20:37:00Z</updated><content type="html">&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #4f81bd;"&gt;&lt;span style="font-family: Cambria;"&gt;&lt;span style="font-size: small;"&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Active Directory Federation Services (AD FS) 2.0 has just released its first Management Pack (MP) for &lt;b style="mso-bidi-font-weight: normal;"&gt;Microsoft System Center Operations Manager 2007 Service Pack 1 (SP1) and R2&lt;/b&gt;!! We have worked on it for quite some time, and it is exciting to finally get it out! &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;As you may know, there is an MP for AD FS v1. This MP is for AD FS 2.0. The goal of the AD FS 2.0 MP is to help your IT operators easily monitor the health of the AD FS 2.0 service and its different parts as well as to provide them with troubleshooting content in case some issues arise. If it&amp;rsquo;s your first time hearing about MP, don&amp;rsquo;t worry. Let&amp;rsquo;s do a quick overview by first explaining what an MP is and why you may want to use one.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;Note:&lt;/i&gt;&lt;/b&gt;&lt;i style="mso-bidi-font-style: normal;"&gt; if you already &lt;/i&gt;have &lt;i style="mso-bidi-font-style: normal;"&gt;System Center Operations Manager 2007, you can download and use the AD FS 2.0 MP for free! For details about System Center Operations Manager 2007 licensing, see &lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=199557"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span style="font-family: Calibri; color: #0000ff;"&gt;How to Buy Operations Manager 2007 R2&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="font-size: medium;"&gt;What is a Management Pack?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;&lt;b style="mso-bidi-font-weight: normal;"&gt;A management pack&lt;/b&gt; (MP) contains predefined monitoring rules and other settings to work with System Center Operations Manager. Each product defines its own MP. You must import the product&amp;rsquo;s MP into System Center Operations Manager to use it. After it is imported, the monitoring agent of System Center Operations Manager will run on the computers to monitor the health of a specific service or application based on the monitoring settings that are defined in the MP. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;The predefined settings in the MP include the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Discovery information that makes it possible for System Center Operations Manager to automatically detect and begin monitoring services and applications&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Monitoring and alert rules that change the health state of the monitored services or applications in System Center Operations Manager and generate alerts when the corresponding health condition is detected&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;A knowledge base that contains error and troubleshooting information that is associated with the alerts&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri; color: #000000;"&gt;For more information about the MP concept and System Center Operations Manager, see &lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkId=199558"&gt;&lt;span style="font-family: Calibri; color: #0000ff;"&gt;Microsoft Systems Center Operations Manager&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="font-size: medium;"&gt;Benefit of using a Management Pack&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 30pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;We mentioned that an MP provides the monitoring mechanism for services and applications. &lt;b style="mso-bidi-font-weight: normal;"&gt;The audience for a MOM Pack is primarily IT operators&lt;/b&gt;. They care about whether their application is healthy, the users of their application are happy, and how well the parts of their applications work together. IT operators can use the MP to pinpoint what is broken so that they do not need to do a manual diagnosis. By using an MP, the IT operators can have a central view of the health of multiple services or applications that they are monitoring, and they can make sure that such health information is up to date as things change. Also, the MP provides a knowledge base, which IT operators can use to quickly troubleshoot a problem without looking at other resources.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;So, we talked about some basic concepts of MP; let&amp;rsquo;s take a look at &lt;b style="mso-bidi-font-weight: normal;"&gt;AD FS 2.0 MP&lt;/b&gt;. As you may know, AD FS 2.0 is a security token service that authenticates users and generates security tokens. We can logically divide AD FS 2.0 into different parts. You can use the AD FS 2.0 MP to monitor the health of each part of AD FS 2.0 service as well as the overall health of AD FS 2.0 service. The primary mechanism that the AD FS 2.0 MP uses for health monitoring is the AD FS 2.0 events. Of course, you may think &amp;ldquo;I can use Event Viewer to do the same thing.&amp;rdquo; However, there are &lt;b style="mso-bidi-font-weight: normal;"&gt;benefits&lt;/b&gt; &lt;b style="mso-bidi-font-weight: normal;"&gt;of using AD FS 2.0 MP&lt;/b&gt; instead of using Event Viewer: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;First, the AD FS 2.0 MP does the filtering and analysis of the events for you. It alerts you only when it is very likely that there is something broken (compared to intermittent problems). Also, it alerts you only once so that you won&amp;rsquo;t be flooded with hundreds of events, which makes it hard to figure out the root cause of a problem. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Second, besides reactive monitoring, AD FS 2.0 MP also provides proactive monitoring, which can detect a problem before it happens. For example, AD FS 2.0 MP proactively monitors the expiration status of the Secure Sockets Layer (SSL) certificate that is configured for the federation passive website. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Third, the AD FS 2.0 MP separates and scopes down the issues to a particular AD FS 2.0 component and provides rich knowledge about the issues, all of which help you troubleshoot quickly. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l2 level1 lfo3;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Fourth, AD FS 2.0 MP also integrates performance monitoring and provides a diagram view of the performance. It is very easy for you to tell the performance pattern from the diagram. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The AD FS 2.0 MP provides &lt;b style="mso-bidi-font-weight: normal;"&gt;10&lt;/b&gt; &lt;b style="mso-bidi-font-weight: normal;"&gt;localized versions, one for each supported language&lt;/b&gt;, including the following: &lt;b style="mso-bidi-font-weight: normal;"&gt;Spanish&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;French&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Italian&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Japanese&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Korean&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Chinese &lt;/b&gt;(&lt;b style="mso-bidi-font-weight: normal;"&gt;China&lt;/b&gt;), &lt;b style="mso-bidi-font-weight: normal;"&gt;Chinese &lt;/b&gt;(&lt;b style="mso-bidi-font-weight: normal;"&gt;Taiwan&lt;/b&gt;), &lt;b style="mso-bidi-font-weight: normal;"&gt;Russian&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;German&lt;/b&gt;, and&lt;b style="mso-bidi-font-weight: normal;"&gt; Portugese-Brasilian&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Ok, that&amp;rsquo;s enough conceptual talk. Let&amp;rsquo;s look at this stuff in action! &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="font-size: medium;"&gt;What&amp;rsquo;s in the AD FS 2.0 MP?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;We have talked about what an MP is and what the benefits of using an AD FS 2.0 MP are. So, what&amp;rsquo;s in an AD FS 2.0 MP, and how do we use it? Let&amp;rsquo;s take a closer look at the AD FS 2.0 MP. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;The AD FS 2.0 MP provides an intuitive way for IT operators to get an overview the topology of AD FS 2.0 deployments in a farm, as well as the AD FS 2.0 configurations of a single instance. It also makes it possible for IT operators to monitor the health of AD FS 2.0 deployments and diagnose and fix the issues that affect AD FS 2.0 health. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;In detail, the AD FS 2.0 MP has the following &lt;b style="mso-bidi-font-weight: normal;"&gt;functionality&lt;/b&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: 'Arial','sans-serif'; mso-fareast-font-family: Arial;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;bull;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Discovers AD FS 2.0 deployment (in either the federation server role or the federation server proxy role) in a farm or on a single, monitored computer &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: 'Arial','sans-serif'; mso-fareast-font-family: Arial;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;bull;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Discovers different AD FS 2.0 parts&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;that have been deployed on the monitored computer &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: 'Arial','sans-serif'; mso-fareast-font-family: Arial;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;bull;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Monitors the health of different AD FS 2.0 parts and generates appropriate alerts &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: 'Arial','sans-serif'; mso-fareast-font-family: Arial;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;bull;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Monitors the performance of AD FS 2.0 &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2; tab-stops: list .5in;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: 'Arial','sans-serif'; mso-fareast-font-family: Arial;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;bull;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Provides diagnostic knowledge for each alert &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="font-size: small;"&gt;AD FS 2.0 Views &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;The following illustration shows what the AD FS 2.0 views in System Center Operations Manager 2007 looks like. As you can see, the views include the &lt;b style="mso-bidi-font-weight: normal;"&gt;State View&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Alerts View&lt;/b&gt;, &lt;b style="mso-bidi-font-weight: normal;"&gt;Events View&lt;/b&gt;, and &lt;b style="mso-bidi-font-weight: normal;"&gt;Performance View&lt;/b&gt;. All of these views are defined for each AD FS 2.0 role&amp;mdash;federation server or federation server proxy. In the topmost &lt;b style="mso-bidi-font-weight: normal;"&gt;State View&lt;/b&gt;, you can see the overall health state of the AD FS 2.0 service, as shown below. In this example, there is no federation server proxy discovered; so, the health state column for Federation Server Proxies is empty. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;
&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&amp;nbsp;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;img height="235" width="462" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/6786.view_2B00_state.jpg" border="0" /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;The following illustration shows the &lt;b style="mso-bidi-font-weight: normal"&gt;Performance View&lt;/b&gt; of one of the AD FS 2.0 federation servers being monitored. The performance area of the AD FS 2.0 service that is being monitored is &lt;b style="mso-bidi-font-weight: normal"&gt;Token Request per second&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="mso-no-proof: yes;"&gt;&lt;v:shapetype coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f" id="_x0000_t75"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;v:imagedata src="file:///C:\Users\luzhao\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&lt;/span&gt;&lt;/v:imagedata&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="color: #4f81bd;"&gt;&lt;span style="font-family: Cambria;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;img height="166" width="446" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/8267.performance.jpg" border="0" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h3 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="color: #4f81bd;"&gt;&lt;span style="font-family: Cambria;"&gt;&lt;span style="font-size: small;"&gt;AD FS 2.0 Discovery&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;The AD FS 2.0 MP can discover all the AD FS 2.0 instances in a farm. The following illustration shows an example of a &lt;b style="mso-bidi-font-weight: normal;"&gt;State View&lt;/b&gt; of two AD FS 2.0 federation servers in a Windows Internal Database (WID) farm. As you can see, the parts that AD FS 2.0 is monitoring for the federation server are &lt;b style="mso-bidi-font-weight: normal;"&gt;Trust Management&lt;/b&gt; and &lt;b style="mso-bidi-font-weight: normal;"&gt;Authentication&lt;/b&gt;, which contain token issuance and token acceptance monitoring; &lt;b style="mso-bidi-font-weight: normal;"&gt;WID Sync&lt;/b&gt; for the synchronization among primary and secondary computers, &lt;b style="mso-bidi-font-weight: normal;"&gt;Web Sites&lt;/b&gt;, and &lt;b style="mso-bidi-font-weight: normal;"&gt;Certificate Management&lt;/b&gt;. For the federation server proxy, the parts that AD FS 2.0 MP monitors are &lt;b style="mso-bidi-font-weight: normal;"&gt;Authentication &lt;/b&gt;and &lt;b style="mso-bidi-font-weight: normal;"&gt;Web Sites&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/0777.FS_5F00_State.jpg" border="0" /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Besides monitoring the health of these parts, the AD FS 2.0 MP also retrieves the important configuration information for each part (shown in the detail view in the previous illustration). In the previous example, the AD FS 2.0 MP detects that those two computers belong to a WID farm and that the highlighted computer in the farm is the primary computer in the farm. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;You can also open the &lt;b style="mso-bidi-font-weight: normal;"&gt;Diagram View&lt;/b&gt; to get an idea of the overall deployment topologies of the AD FS 2.0 servers and proxies. All the stand-alone federation servers are grouped under a single federation service node, and each farm has its own node. The following illustrationi shows an example. The AD FS 2.0 MP has detected an AD FS 2.0 farm that consists of two federation servers and one stand-alone AD FS 2.0 instance on the Adfsidentity computer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;
&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;img height="219" width="252" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/1106.Diagram-view_5F00_1.jpg" border="0" /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;The following illustration shows all the monitored AD FS 2.0 parts on one of the federation servers in the AD FS 2.0 farm.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;img height="202" width="412" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/5707.Diagram-view.jpg" border="0" /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;
&lt;h3 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="color: #4f81bd;"&gt;&lt;span style="font-family: Cambria;"&gt;&lt;span style="font-size: small;"&gt;AD FS 2.0 Monitoring &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;The AD FS 2.0 MP monitors the AD FS 2.0 service, based on two mechanisms: &lt;b style="mso-bidi-font-weight: normal;"&gt;Events &lt;/b&gt;and &lt;b style="mso-bidi-font-weight: normal;"&gt;Scripts&lt;/b&gt;. If any monitored event occurs, it changes the health state of the related AD FS 2.0 component or generates an alert or both. AD FS 2.0 also has its own &lt;b style="mso-bidi-font-weight: normal;"&gt;PowerShell based scripts&lt;/b&gt; that run periodically to monitor the health of different AD FS 2.0 parts proactively (See &lt;a href="http://go.microsoft.com/fwlink/?LinkId=199559"&gt;&lt;span style="color: #0000ff;"&gt;AD FS 2.0 MP Guide&lt;/span&gt;&lt;/a&gt; for a complete set of AD FS 2.0 monitoring scripts). Also, we have defined custom overrides in the MP for different script-based objects apart from the standard objects that System Center Operations Manager provides. Users can override the default values, such as the frequency, to run the scripts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;The health state of AD FS 2.0 parts are changes, based on the rules that are defined in the MP. It is &lt;b style="mso-bidi-font-weight: normal;"&gt;reset&lt;/b&gt; &lt;b style="mso-bidi-font-weight: normal;"&gt;to Healthy state&lt;/b&gt; in two cases automatically: &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;1.&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;When there is a clear counter event that indicates that the issue has been resolved. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;2.&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;After some period of time, if there is no indication that this problem still persists, the health state resets. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;The default time for 2 is 15 minutes, which the user can override. Besides these two conditions, you have to manually reset the AD FS 2.0 health state after you make sure that the corresponding issue has been resolved.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;The following is an illustration of the &lt;b style="mso-bidi-font-weight: normal;"&gt;Alert View&lt;/b&gt; that shows the Alerts that the AD FS 2.0 MP generated. The following example is an alert for Trust Management because AD FS 2.0 failed to create the Federation Metadata document. The knowledge for this alert contains a summary of this monitoring, a description of the cause of this alert, and the detailed steps for resolution. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;
&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;&lt;img height="313" width="507" src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/0474.Alert.jpg" border="0" /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;o:p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;To avoid duplicate alerts, the AD FS 2.0 MP has implemented a monitoring mechanism, provided by System Center Operations Manager 2007, called &lt;b style="mso-bidi-font-weight: normal;"&gt;Alert Suppression&lt;/b&gt;. In events occur, the same events may be generated multiple times for the same issue and continue to be generated as long as the issue still exists. For example, federation passive requests may fail because the web.config file is corrupted. When this issue is mapped to an alert in the AD FS 2.0 MP, only one alert is generated, even when this issue triggers a lot of events. Basically, the AD FS 2.0 MP analyzes the events per root cause and generates an alert per root cause accordingly.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Also, to avoid over-alerting, AD FS 2.0 refrains from generating alerts for issues that may be caused by intermittent problems. For example, the AD FS 2.0 MP waits for multiple occurrences of events that indicate that the AD FS 2.0 service cannot reach a domain controller before it generates an alert. For a detailed look at how the AD FS 2.0 MP implements alert suppression and event counting for key monitoring scenarios, see the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=199559"&gt;&lt;span style="color: #0000ff;"&gt;AD FS 2.0 MP Guide&lt;/span&gt;&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;To summarize:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The AD FS 2.0 MP uses events and scripts to monitor the health of the AD FS 2.0 service. Scripts are used for proactive monitoring, such as detecting whether the federation passive website is up and running and whether the SSL certificate is expiring.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The health state of the AD FS 2.0 service and its parts may be autoreset or need manual reset, depending on the conditions. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The AD FS 2.0 MP generates alerts when an issue is detected. An alert contains rich knowledge that can help troubleshooting.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;&amp;middot;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The AD FS 2.0 MP implements alert suppression and event counting so that your Alert View is not flooded with duplicate alerts or alerts that may not indicate a persistent issue.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;h2 style="margin: 10pt 0in 0pt;"&gt;&lt;span style="font-size: medium;"&gt;&lt;span style="color: #4f81bd;"&gt;&lt;span style="font-family: Cambria;"&gt;Where to download AD FS 2.0 MP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Feel like you have a good understanding of what AD FS 2.0 MP has to offer? Give it a try! You can download the AD FS 2.0 MP and AD FS 2.0 MP Guide at &lt;a href="http://go.microsoft.com/fwlink/?LinkId=199065"&gt;&lt;span style="color: #0000ff;"&gt;Active Directory Federation Services 2.0 (ADFS) Monitoring Management Pack&lt;/span&gt;&lt;/a&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;The AD FS 2.0 MP supports localization of 10 languages. Choose the language of the MP in the drop-down list when you download the MP. This action redirects you to the localized download page where you can download the localized MP guide as well.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Have fun trying it out! &lt;span style="font-family: Wingdings; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-char-type: symbol; mso-symbol-font-family: Wingdings;"&gt;&lt;span style="mso-char-type: symbol; mso-symbol-font-family: Wingdings;"&gt;J&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10047175" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /><category term="MOM Pack" scheme="http://blogs.msdn.com/b/card/archive/tags/MOM+Pack/" /><category term="Windows Identity Foundation" scheme="http://blogs.msdn.com/b/card/archive/tags/Windows+Identity+Foundation/" /></entry><entry><title>AD FS 2.0 Step-by-Step Guide: Federation with Oracle Identity Federation</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/08/02/ad-fs-2-0-step-by-step-guide-federation-with-oracle-identity-federation.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/08/02/ad-fs-2-0-step-by-step-guide-federation-with-oracle-identity-federation.aspx</id><published>2010-08-02T22:56:37Z</published><updated>2010-08-02T22:56:37Z</updated><content type="html">&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;We have published a step-by-step guide on how to configure AD FS 2.0 and Oracle Identity Federation to federate using the SAML 2.0 protocol.&amp;nbsp; You can view the guide either as a &lt;a href="http://technet.microsoft.com/en-us/library/ff849212(WS.10).aspx"&gt;web page&lt;/a&gt; or in &lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=46bd1cc0-cbe1-4426-875d-428b25b65f1a"&gt;docx format&lt;/a&gt;.&amp;nbsp; This is the second in a series of these guides; the guides are also available on the &lt;a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx"&gt;AD FS 2.0 Step-by-Step and How To Guides&lt;/a&gt; page.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10045181" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /></entry><entry><title>AD FS 2.0 Step-by-Step Guide: Federation with CA Federation Manager</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/07/16/ad-fs-2-0-step-by-step-guide-federation-with-ca-federation-manager.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/07/16/ad-fs-2-0-step-by-step-guide-federation-with-ca-federation-manager.aspx</id><published>2010-07-16T19:10:13Z</published><updated>2010-07-16T19:10:13Z</updated><content type="html">&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;We have published a step-by-step guide on how to configure AD FS 2.0 and CA Federation Manager to federate using the SAML 2.0 protocol.&amp;nbsp; You can view the guide either as a &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ff754295(WS.10).aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;web page&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; or in &lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=fef76ca4-5677-4356-afb1-196d8f92dc79"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;docx format&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;.&amp;nbsp; This is the first in a series of these guides; the guides are also available on the &lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd727938(WS.10).aspx"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;AD FS 2.0 Step-by-Step and How To Guides&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; page.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10039250" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="whitepapers" scheme="http://blogs.msdn.com/b/card/archive/tags/whitepapers/" /><category term="SAML" scheme="http://blogs.msdn.com/b/card/archive/tags/SAML/" /><category term="ADFS" scheme="http://blogs.msdn.com/b/card/archive/tags/ADFS/" /></entry><entry><title>The Federated Identity Forum</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/07/15/the-federated-identity-forum.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/07/15/the-federated-identity-forum.aspx</id><published>2010-07-15T19:12:52Z</published><updated>2010-07-15T19:12:52Z</updated><content type="html">&lt;p&gt;In order to consolidate our support for our Federated Identity platforms, we are removing the 'Email the Blog Author' functionality of this blog and reccomending that anyone with questions related to the AD FS, WIF, or CardSpace head over to our forum, located &lt;a href="http://social.msdn.microsoft.com/Forums/en-US/Geneva/threads"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This forum is actively monitored by members of the product group, as well as MVPs and the community.&amp;nbsp; We hope that we will better be able to provide support and answer your questions by directing them all through this single forum. &lt;/p&gt;
&lt;p&gt;-The AD FS, WIF, and CardSpace teams&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10038792" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>WIF Workshops, June 2010 update for Identity Training Kit, and a Patterns &amp; Practices Guide on “Claims-based Identity”</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/06/30/wif-workshops-june-2010-update-for-identity-training-kit-and-a-patterns-amp-practices-guide-on-claims-based-identity.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/06/30/wif-workshops-june-2010-update-for-identity-training-kit-and-a-patterns-amp-practices-guide-on-claims-based-identity.aspx</id><published>2010-06-30T18:26:22Z</published><updated>2010-06-30T18:26:22Z</updated><content type="html">&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;a href="http://blogs.msdn.com/b/vbertocci"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Vittorio&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt; in DPE (Developer Platform and Evangelism) team has been touring the world evangelizing claims based identity model and WIF. As a result, there is an excellent set of resources for you to learn WIF! Check out the &lt;/span&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;10-part &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a target="_blank" href="http://channel9.msdn.com/tags/WIF-Workshop/"&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;WIF Workshop recordings&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt; that cover the topics such as &lt;/span&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;basics of claims-based identity and WIF, the scenarios that WIF enables, how WIF plugs into the ASP.NET pipeline, how WIF plays with WCF, and how WIF plays a key role for identity management in Azure.&lt;/span&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt; &lt;span lang="EN"&gt;If you want to grab the presentation decks of these WIF Workshops, check out the latest June 2010 update of the &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://bit.ly/cWyWZ2"&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Identity Developer Training Kit&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;a href="http://blogs.msdn.com/members/eugeniop/"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Eugenio Pace&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; in Patterns &amp;amp; Practices team has published a guide on &amp;ldquo;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ff423674.aspx"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Claims-based Identity and Access Control&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&amp;rdquo;. It is an excellent guide to understand the benefits of claims-based identity model when you are planning a new application or making changes to existing applications that require user identity information. You can also purchase a hard copy of this guide from your favorite online book stores.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Other References and Resources:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;a href="http://blogs.msdn.com/b/windowsazure/archive/2010/06/29/new-training-video-outlines-use-of-wif-in-windows-azure.aspx"&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Azure team&amp;rsquo;s recent blog post on WIF in Azure&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ee748484.aspx"&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;WIF Product Documentation on MSDN&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; background: white; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"&gt;&lt;a href="http://download.microsoft.com/download/7/D/0/7D0B5166-6A8A-418A-ADDD-95EE9B046994/WindowsIdentityFoundationWhitepaperForDevelopers-RTW.pdf"&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;WIF Whitepaper for Developers&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="EN" style="color: #0070c0; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;o:p&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Happy coding with WIF!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Sesha Mani &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span lang="EN" style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-ansi-language: EN;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;On behalf of WIF Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10033050" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="Azure" scheme="http://blogs.msdn.com/b/card/archive/tags/Azure/" /><category term="WIF" scheme="http://blogs.msdn.com/b/card/archive/tags/WIF/" /></entry><entry><title>Using Federation Metadata to establish a Relying Party Trust in AD FS 2.0</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/06/25/using-federation-metadata-to-establish-a-relying-party-trust-in-ad-fs-2-0.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/06/25/using-federation-metadata-to-establish-a-relying-party-trust-in-ad-fs-2-0.aspx</id><published>2010-06-25T00:38:28Z</published><updated>2010-06-25T00:38:28Z</updated><content type="html">&lt;p&gt;Trust relationships are of course the &lt;i&gt;sine qua non&lt;/i&gt; of AD FS 2.0. Relying Party Trusts or Claims Provider Trusts are necessary before AD FS 2.0 can provide benefit to any organization. That said, the establishment and maintenance of these relationships can be a time consuming task. Fortunately there are methods available that make this job significantly easier. AD FS provides three methods for creating Relying Party Trusts and Claims Provider Trusts. Manual entry of the necessary information is the most familiar method, but also the most time consuming and difficult to maintain. Additionally a trust can be created by importing &amp;quot;federation metadata&amp;quot;, that is, data that describes a Relying Party or Claims Provider and allows for easy creation of the corresponding trust. A federation metadata document is an XML document that conforms to the WS-Federation 1.2 schema. Federation metadata may be imported from a file, or the partner may make the data available via https. The latter method provides the most straightforward method for creating a partnership and greatly simplifies any ongoing maintenance that may be required.&lt;/p&gt;  &lt;p&gt;Manually creating a Relying Party Trust requires that the Administrator supply a fair amount of information that must be obtained from the partner organization through some out of band communication. This information includes the URLs for the WS-Federation Passive protocol and\or the SAML 2.0 Web SSO protocol, one or more relying party identifiers and, typically, the X.509 Certificate used to encrypt any claims sent to the relying party. Figure 1 below shows the various pages of the Add Relying Party Trust Wizard that must be navigated in order to create a relying party trust.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8272.clip_5F00_image0024_5F00_2493D5CB.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image002[4]" border="0" alt="clip_image002[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8765.clip_5F00_image0024_5F00_thumb_5F00_6B10C5D3.jpg" width="365" height="293" /&gt;&lt;/a&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/5148.clip_5F00_image0044_5F00_43D67C9E.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image004[4]" border="0" alt="clip_image004[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/2018.clip_5F00_image0044_5F00_thumb_5F00_1172A91F.jpg" width="365" height="293" /&gt;&lt;/a&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0755.clip_5F00_image0064_5F00_6A385FE9.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image006[4]" border="0" alt="clip_image006[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8272.clip_5F00_image0064_5F00_thumb_5F00_42FE16B4.jpg" width="365" height="293" /&gt;&lt;/a&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/7608.clip_5F00_image0084_5F00_02C7FD3A.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image008[4]" border="0" alt="clip_image008[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/3173.clip_5F00_image0084_5F00_thumb_5F00_097B06BD.jpg" width="365" height="293" /&gt;&lt;/a&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0842.clip_5F00_image0104_5F00_7B3C8DCC.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image010[4]" border="0" alt="clip_image010[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8206.clip_5F00_image0104_5F00_thumb_5F00_54024497.jpg" width="365" height="293" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 1 - Manually adding a relying party trust.&lt;/p&gt;  &lt;p&gt;Once the relying party trust is established, it must also be maintained. It is possible that one or more of the URL's that identify the relying party may change, or the set of claims that the relying party will accept might change, but more likely, the X.509 Certificate used for encryption will have to be replaced, either because it has expired or because it has become compromised. Managing the updating of encryption certificates across an organization that might contain hundreds, or thousands, of relying parties presents a daunting challenge.&lt;/p&gt;  &lt;p&gt;Lets explore how we create a Relying Party Trust using federation metadata.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0552.clip_5F00_image0124_5F00_07867B8C.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image012[4]" border="0" alt="clip_image012[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0640.clip_5F00_image0124_5F00_thumb_5F00_5154DD6F.jpg" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 2 - Options for entering data for a Relying Party Trust&lt;/p&gt;  &lt;p&gt;As you can see from figure 2, it is possible to provide the metadata in the form of a file, as well as by specifying an https address. For purposes of this article I will confine our discussion to the case where the metadata is provided via https.&lt;/p&gt;  &lt;p&gt;Each AD FS 2.0federation servers configured by default to publish metadata describing itself via https. If you click on the Service\Endpoints folder in the AD FS 2.0 snap-in you can see the highlighted endpoint in question as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/5751.clip_5F00_image0144_5F00_7103B737.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image014[4]" border="0" alt="clip_image014[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8081.clip_5F00_image0144_5F00_thumb_5F00_70978442.jpg" width="711" height="504" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 3 -Showing the federation metadata endpoint provided by AD FS 2.0&lt;/p&gt;  &lt;p&gt;To see what the actual XML looks like you can enter the endpoint into your web browser, as shown below:    &lt;br /&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/4760.clip_5F00_image0164_5F00_5B39CEDA.gif"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image016[4]" border="0" alt="clip_image016[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/7180.clip_5F00_image0164_5F00_thumb_5F00_5ACD9BE5.gif" width="639" height="529" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 4 - Example of a Federation Metadata document describing the information that is published about a specific Federation Service&lt;/p&gt;  &lt;p&gt;I'm not going to review the structure of the federation metadata document here, except to note that it is a signed document and should not be edited or reformatted by hand. Anyone who is interested in the details of the schema, can find the specification at . &lt;a href="http://docs.oasis-open.org/wsfed/federation/v1.2/ws-federation.pdf"&gt;http://docs.oasis-open.org/wsfed/federation/v1.2/ws-federation.pdf&lt;/a&gt; Instead I want to walk through an example of how to establish a Relying Party Trust using federation metadata.&lt;/p&gt;  &lt;p&gt;The first step, of course is to launch the Add Relying Party Trust Wizard and navigate to the select data source page:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/5344.clip_5F00_image0184_5F00_735D3935.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image018[4]" border="0" alt="clip_image018[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/7418.clip_5F00_image0184_5F00_thumb_5F00_6EE6B86E.jpg" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 5 - Providing a federation metadata endpoint to the Add Relying Party Trust wizard&lt;/p&gt;  &lt;p&gt;If you are interested in creating a trust using federation metadata but don't have a partner handy that provides metadata, it is perfectly feasible to have AD FS create a trust with itself. Of course, this is obviously of little use in the real world, but it's perfectly suitable for purposes of illustration. The first step is to provide the https address of the metadata document. If you know the full URL you can provide it, or you can simply enter the host name, and AD FS will attempt to find the data at the most common location. In this case enter the name of your host machine (not fs.contoso.com) and hit the next button. AD FS will read the available metadata and use it to construct the Relying Party Trust.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/2625.clip_5F00_image0204_5F00_2791627C.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image020[4]" border="0" alt="clip_image020[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/5023.clip_5F00_image0204_5F00_thumb_5F00_2E446BFF.jpg" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 6 - Prompting for the relying party display name after reading federation metadata&lt;/p&gt;  &lt;p&gt;As we can see the wizard path is considerably shorter than in the manual entry case. SAML metadata does not typically provide a display name for the relying party trust, so we are prompted to provide one, along with any comments we want to make about the relying party. Then we hit the &lt;b&gt;Next&lt;/b&gt; button, which takes us to the &lt;b&gt;Choose Issuance Authorization Rules&lt;/b&gt; page.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/3276.clip_5F00_image0224_5F00_2005F30F.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image022[4]" border="0" alt="clip_image022[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/6835.clip_5F00_image0224_5F00_thumb_5F00_0D50F958.jpg" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 7 - The Choose Issuance Authorization Rules page&lt;/p&gt;  &lt;p&gt;In this case, we're going to deny all users access to the relying party for now. Later we can add some issuance authorization rules to enable access to the relying party. We hit the &lt;b&gt;Next&lt;/b&gt; button to go on to the review page.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/2046.clip_5F00_image0244_5F00_45FBA365.gif"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image024[4]" border="0" alt="clip_image024[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/6825.clip_5F00_image0244_5F00_thumb_5F00_17A21DB8.gif" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 8 - Reviewing the relying party trust that was created from metadata.&lt;/p&gt;  &lt;p&gt;Here we can review the Relying Party Trust that we are about to create. If we examine the various tabs on the page, we can see that the Identifier URLs, encryption and signature certificates, list of accepted claims, endpoints etc., have all been provided via the metadata.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/5355.clip_5F00_image0264_5F00_45233D7B.gif"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image026[4]" border="0" alt="clip_image026[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/2318.clip_5F00_image0264_5F00_thumb_5F00_2BBB3A41.gif" width="640" height="513" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 9 - The encryption certificate provided by the federation metadata&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/1134.clip_5F00_image0284_5F00_444AD791.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image028[4]" border="0" alt="clip_image028[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/3716.clip_5F00_image0284_5F00_thumb_5F00_43DEA49C.jpg" width="581" height="466" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 10 - The list of accepted claims provided by federation metadata&lt;/p&gt;  &lt;p&gt;After reviewing the configuration of the relying party trust, we hit the &lt;b&gt;Next&lt;/b&gt; button to add it to the database. In figure 11, below we see the successfully created relying party trust.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/8562.clip_5F00_image0304_5F00_0A5B94A5.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image030[4]" border="0" alt="clip_image030[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/7827.clip_5F00_image0304_5F00_thumb_5F00_4E2FC8FC.jpg" width="640" height="454" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 11 - Showing the newly created relying party trust&lt;/p&gt;  &lt;p&gt;Now I mentioned previously that federation metadata not only facilitates the creation of trusts, but also their maintenance. To show this in more detail, let’s open the properties dialog for the Contoso relying party.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0576.clip_5F00_image0324_5F00_6DDEA2C4.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image032[4]" border="0" alt="clip_image032[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/0160.clip_5F00_image0324_5F00_thumb_5F00_0D8D7C8D.jpg" width="412" height="472" /&gt;&lt;/a&gt;    &lt;br /&gt;Figure 12 - The properties page for the Contoso relying party trust&lt;/p&gt;  &lt;p&gt;In figure 12 above we see the properties dialog, with the &lt;b&gt;Monitoring&lt;/b&gt; tab displayed. This tab governs how AD FS manages the updating of this relying party trust. You can see that the &lt;b&gt;Monitor relying party&lt;/b&gt; check box is checked. This indicates that AD FS will periodically check the &lt;b&gt;Federation Metadata URL&lt;/b&gt; shown in the dialog and compare it with the current state of the relying party trust. You will also notice that the &lt;b&gt;Automatically update relying party&lt;/b&gt; checkbox is checked. This tells AD FS to automatically update the relying party trust in responses to changes in the metadata. With this option enabled, we do not have to worry about certificates expiring or being replaced - any changes made to the partner will be reflected in the metadata and automatically moved into the database. The &lt;b&gt;Monitoring&lt;/b&gt; tab also displays the date on which the metadata was last checked as well as the date upon which the last update was performed. Events are also logged when an update is performed.&lt;/p&gt;  &lt;p&gt;Note that if the &lt;b&gt;Automatically update relying party&lt;/b&gt; check box was unchecked, then the monitoring would still continue, but AD FS would not be updated. Instead those relying parties that are no longer in sync with their metadata would be indicated in the UI, as well as in the event log.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/6443.clip_5F00_image0344_5F00_14408610.gif"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image034[4]" border="0" alt="clip_image034[4]" src="http://blogs.msdn.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54-metablogapi/2727.clip_5F00_image0344_5F00_thumb_5F00_33EF5FD8.gif" width="639" height="458" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Figure 13 - Notification that a relying party trust needs to be updated.&lt;/p&gt;  &lt;p&gt;If you refer to figure 13, you will notice that one of the actions available for the Contoso relying party is &lt;b&gt;Update from Federation Metadata...&lt;/b&gt; This command allows the Administrator to force an update from metadata at will. &lt;/p&gt;  &lt;p&gt;Federation Metadata is a powerful tool for managing AD FS 2.0. In future posts we will explore other aspects and techniques for using this data.&lt;/p&gt;  &lt;p&gt;For more information about how to create trusts via federation metadata, see the following topics in the AD FS 2.0 Deployment Guide:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd807128(WS.10).aspx"&gt;Create a Claims Provider Trust Using Federation Metadata&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd807132(WS.10).aspx"&gt;Create a Relying Party Trust Using Federation Metadata&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10029911" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>A Quick Walkthrough: Setting up AD FS SAML Federation with a Shibboleth SP</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/06/21/a-quick-walkthrough-setting-up-ad-fs-saml-federation-with-a-shibboleth-sp.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/06/21/a-quick-walkthrough-setting-up-ad-fs-saml-federation-with-a-shibboleth-sp.aspx</id><published>2010-06-21T17:57:00Z</published><updated>2010-06-21T17:57:00Z</updated><content type="html">&lt;p&gt;Shibboleth is an open-source software project that provides SAML and WS-Federation protocol support, and is commonly found throughout the higher education market.&amp;nbsp; Since it talks standard protocols, AD FS can be configured to grant access to resources protected by Shibboleth.&lt;/p&gt;
&lt;p&gt;At the end of this blog post, you'll have a lab machine with an ASP.Net web page protected by Shibboleth and federating to your AD FS identity provider.&amp;nbsp; We'll start from scratch and quickly build a functioning federation.&lt;/p&gt;
&lt;p&gt;This is a great way to explore Shibboleth/AD FS interoperability in a test environment before making the corresponding changes on your live Shibboleth site.&lt;/p&gt;
&lt;h1&gt;Prerequisites&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;AD FS 2.0 installed and working at &lt;a href="https://your-domain/adfs/ls/"&gt;https://your-domain/adfs/ls/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For simplicity's sake, this post will install Shibboleth onto the same machine as AD FS.&amp;nbsp; It also assumes the default AD FS identifier is used:&amp;nbsp; &lt;a href="https://your-domain.com/adfs/services/trust"&gt;https://your-domain.com/adfs/services/trust&lt;/a&gt; &lt;/p&gt;
&lt;h1&gt;Install Shibboleth&lt;/h1&gt;
&lt;p&gt;Visit the &lt;a href="http://shibboleth.internet2.edu/downloads.html"&gt;Shibboleth download site&lt;/a&gt; and install the 32-bit or 64-bit SP package as appropriate to your server.&amp;nbsp; Restart your computer when prompted.&lt;/p&gt;
&lt;h1&gt;Configure Shibboleth&lt;/h1&gt;
&lt;p&gt;Edit c:\opt\shibboleth-sp\etc\shibboleth\shibboleth2.xml as follows (&lt;b&gt;bold&lt;/b&gt; indicates text you'll need to change to reflect your environment):&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Replace &amp;lt;Site id="1" name="sp.example.org"/&amp;gt; with &amp;lt;Site id="1" name="&lt;b&gt;your-domain.com&lt;/b&gt;"/&amp;gt;&lt;/li&gt;
&lt;li&gt;Replace &amp;lt;Host name="sp.example.org"&amp;gt; with &amp;lt;Host name="&lt;b&gt;your-domain.com&lt;/b&gt;"&amp;gt;&lt;/li&gt;
&lt;li&gt;Enable request/response signing (necessary for single logout to work) by setting the signing attribute of the ApplicationDefaults element to true&lt;/li&gt;
&lt;li&gt;Set the entityID attribute of the ApplicationDefaults to https://&lt;b&gt;your-domain.com&lt;/b&gt;/shibboleth&lt;/li&gt;
&lt;li&gt;Under the Sessions element, change the first SessionInititator example to refer to your AD FS instance by setting the entityID attribute to &lt;a href="https://your-domain.com/adfs/services/trust"&gt;https://&lt;b&gt;your-domain.com&lt;/b&gt;/adfs/services/trust&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Tell Shibboleth where to find AD FS's metadata. Under the MetadataProvider element, add:&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="PADDING-LEFT: 60px"&gt;&amp;lt;MetadataProvider &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; type="XML"&lt;/p&gt;
&lt;p style="PADDING-LEFT: 60px"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uri="&lt;b&gt;https://your-domain.com/FederationMetadata/2007-06/FederationMetadata.xml&lt;/b&gt;"&lt;/p&gt;
&lt;p style="PADDING-LEFT: 60px"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; backingFilePath="federation-metadata.xml"&lt;/p&gt;
&lt;p style="PADDING-LEFT: 60px"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; reloadInterval="7200"&lt;br /&gt;/&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7. &amp;nbsp;Restart IIS and the Shibboleth Windows service.&lt;/p&gt;
&lt;p style="padding-left: 60px;"&gt;a. iisreset &lt;br /&gt;b. net stop shibd_Default&lt;br /&gt;c. net start shibd_Default&lt;/p&gt;
&lt;h1&gt;Configure AD FS&lt;/h1&gt;
&lt;p&gt;We'll use PowerShell to add the Shibboleth SP to AD FS.&amp;nbsp; First, create a file in the current directory called "rules.txt" with the following content.&amp;nbsp; This rule is authored in the AD FS claims policy language, and configures a SAML NameID to be emitted for the Shibboleth SP.&amp;nbsp; If you are interested in configuring transient and persistent NameIDs, &lt;a href="http://blogs.msdn.com/card/archive/2010/02/17/name-identifiers-in-saml-assertions.aspx"&gt;refer to our previous blog post on the subject&lt;/a&gt;.&lt;/p&gt;
&lt;p style="PADDING-LEFT: 30px"&gt;@RuleTemplate="LdapClaims"&lt;/p&gt;
&lt;p style="PADDING-LEFT: 30px"&gt;@RuleName="Send E-mail as Name ID"&lt;/p&gt;
&lt;p style="PADDING-LEFT: 30px"&gt;c:[Type="&lt;a href="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname&lt;/a&gt;", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Issuer == "AD AUTHORITY"] &lt;br /&gt;=&amp;gt; issue(&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; store = "Active Directory", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; types = ("&lt;a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier"&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier&lt;/a&gt;"), &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; query = ";mail;{0}", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; param = c.Value);&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Next, run the following PowerShell commands:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Add-PSSnapIn Microsoft.Adfs.PowerShell&lt;/li&gt;
&lt;li&gt;Add-ADFSRelyingPartyTrust -Name "Shibboleth SP" -MetadataUrl &lt;a href="https://your-domain.com/Shibboleth.sso/Metadata"&gt;https://&lt;b&gt;your-domain.com&lt;/b&gt;/Shibboleth.sso/Metadata&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Set-ADFSRelyingPartyTrust -TargetIdentifier &lt;a href="https://your-domain.com/shibboleth%20-IssuanceTransformRulesFiles%20rules.txt"&gt;https://&lt;b&gt;your-domain.com&lt;/b&gt;/shibboleth -IssuanceTransformRulesFiles rules.txt&lt;/a&gt; -SignatureAlgorithm &lt;a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1"&gt;http://www.w3.org/2000/09/xmldsig#rsa-sha1&lt;/a&gt; -IssuanceAuthorizationRules '=&amp;gt; issue(Type = "http://schemas.microsoft.com/authorization/claims/permit", Value = "true"); '&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This will create an AD FS entry for the Shibboleth SP using its metadata.&amp;nbsp; Additionally, it configures the user's e-mail address to be sent as their Name ID and specifies that Shibboleth will be using the SHA-1 hash algorithm for signing its requests.&lt;/p&gt;
&lt;h1&gt;Test Shibboleth&lt;/h1&gt;
&lt;p&gt;Visit &lt;a href="https://your-domain.com/secure/"&gt;https://&lt;b&gt;your-domain.com&lt;/b&gt;/secure/&lt;/a&gt;.&amp;nbsp; Shibboleth should redirect you to AD FS for authentication.&amp;nbsp; Upon success, you'll see... a 404 page.&lt;/p&gt;
&lt;p&gt;Create a default page at c:\inetpub\wwwroot\secure\default.aspx, with the following content:&lt;/p&gt;
&lt;table cellpadding="0" cellspacing="0" border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="561" valign="top"&gt;
&lt;p&gt;&amp;lt;%@ Page Language="C#" %&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;lt;html&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;head&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;title&amp;gt;Shibboleth Echo Page&amp;lt;/title&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/head&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;body&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You are logged in using Shibboleth!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;hr /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;table&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;%&lt;/p&gt;
&lt;p&gt;foreach( string key in Request.ServerVariables )&lt;/p&gt;
&lt;p&gt;{&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if( key.StartsWith("HTTP_SHIB" ) )&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; {&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;tr&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;td&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;%= key %&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/td&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;td&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;%= Request.ServerVariables[ key ] %&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/td&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/tr&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;%&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/p&gt;
&lt;p&gt;}&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/table&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;hr /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;a href="http://blogs.msdn.com/Shibboleth.sso/Logout"&amp;gt;Logout&amp;lt;/a&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/body&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/html&amp;gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;Hit refresh.&amp;nbsp; You'll see the server variables that Shibboleth has populated based on your authentication, as well as a Logout link that you can use to test single logout.&amp;nbsp; Congratulations, you have a working federation with Shibboleth!&lt;/p&gt;
&lt;h1&gt;Common Issues&lt;/h1&gt;
&lt;p&gt;Of course, in the real world, you'll want to send more than just a NameID.&amp;nbsp; Read on for two common issues you may encounter, and how to work around them.&lt;/p&gt;
&lt;h2&gt;Attribute Name Format&lt;/h2&gt;
&lt;p&gt;Shibboleth expects SAML attribute names to have a format of urn:oasis:names:tc:SAML:2.0:attrname-format:uri.&amp;nbsp; By default, AD FS issues attributes with a name format of urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified.&amp;nbsp; If there's a mismatch, Shibboleth will ignore the attribute.&lt;/p&gt;
&lt;p&gt;You can fix this on the Shibboleth side by editing the attribute-map.xml file.&amp;nbsp; Rather than:&lt;/p&gt;
&lt;table cellpadding="0" cellspacing="0" border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="570" valign="top"&gt;
&lt;p&gt;&amp;lt;Attribute name="urn:oid:2.5.4.42" id="givenName"/&amp;gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;Specify the nameFormat attribute to be unspecified:&lt;/p&gt;
&lt;table cellpadding="0" cellspacing="0" border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="570" valign="top"&gt;
&lt;p&gt;&amp;lt;Attribute name="urn:oid:2.5.4.42" id="givenName"&amp;nbsp; &lt;b&gt;nameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"&lt;/b&gt; /&amp;gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;Alternately, you can fix this on the AD FS side by writing a custom claim rule to set the name format. Rather than one rule:&lt;/p&gt;
&lt;table cellpadding="0" cellspacing="0" border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="573" valign="top"&gt;
&lt;p&gt;c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",&amp;nbsp;Issuer == "AD AUTHORITY"]&lt;br /&gt;=&amp;gt; issue(&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; store = "Active Directory", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; types = ("urn:oid:1.3.6.1.4.1.5923.1.1.1.6"), &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; query = ";userPrincipalName;{0}", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; param = c.Value);&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Write two rules, one to retrieve the claim from AD, the other to issue it with a modified NameFormat:&lt;/p&gt;
&lt;table cellpadding="0" cellspacing="0" border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="573" valign="top"&gt;
&lt;p&gt;c:[&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type == "&lt;a href="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname&lt;/a&gt;", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Issuer == "AD AUTHORITY"]&lt;br /&gt;&amp;nbsp;=&amp;gt; add(&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; store = "Active Directory", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; types = ("urn:oid:1.3.6.1.4.1.5923.1.1.1.6"), &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; query = ";userPrincipalName;{0}", &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; param = c.Value); &lt;/p&gt;
&lt;p&gt;&amp;nbsp;c:[&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type == "urn:oid:1.3.6.1.4.1.5923.1.1.1.6"]&lt;br /&gt;&amp;nbsp;=&amp;gt; issue(&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type = c.Type, &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Value = c.Value, &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Issuer = c.Issuer,&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Properties["&lt;a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/attributename"&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claimproperties/attributename&lt;/a&gt;"] = "urn:oasis:names:tc:SAML:2.0:attrname-format:uri");&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;i&gt;If you would like more information about the AD FS policy rules above, have a look at the following TechNet articles for details:&lt;/i&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee913565(WS.10).aspx"&gt;When to Use a Pass Through or Filter Claim Rule&lt;/a&gt;&lt;i&gt;&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee913567(WS.10).aspx"&gt;When to Use a Transform Claim Rule&lt;/a&gt;&lt;i&gt;&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Scoped Attributes&lt;/h2&gt;
&lt;p&gt;Shibboleth supports "scoped attributes".&amp;nbsp; These are attributes in the form of "user@scope".&amp;nbsp; The Shibboleth SP will only process the attribute if the scope portion matches a scope defined in the IdP's metadata.&lt;/p&gt;
&lt;p&gt;This is done via a custom Shibboleth extension element.&amp;nbsp; For details, see the &lt;a href="https://spaces.internet2.edu/display/SHIB/ShibbolethMetadataProfile"&gt;Shibboleth Metadata Profile&lt;/a&gt;.&lt;/p&gt;
&lt;h1&gt;Other Issues?&lt;/h1&gt;
&lt;p&gt;If you run into issues, you may wish to check Shibboleth's log files, located at&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;var\log\shibd.log
&lt;ul&gt;
&lt;li&gt;This contains SAML-specific log messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;var\log\native.log 
&lt;ul&gt;
&lt;li&gt;This contains IIS-specific log messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Still stumped? Check out the &lt;a href="https://spaces.internet2.edu/display/SHIB2/NativeSPTroubleshootingCommonErrors"&gt;SP Troubleshooting&lt;/a&gt; document at the Internet2 site.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10028053" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>AD FS 2.0 Proxy Management</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/06/02/ad-fs-2-0-proxy-management.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/06/02/ad-fs-2-0-proxy-management.aspx</id><published>2010-06-02T18:12:20Z</published><updated>2010-06-02T18:12:20Z</updated><content type="html">&lt;h1&gt;Overview&lt;/h1&gt;
&lt;p&gt;Since the AD FS 2.0 release candidate (RC), the AD FS product team got feedback that the experience of setting up AD FS proxy server and making it work with AD FS Federation Service is cumbersome, as it involves multiple steps across both AD FS proxy and AD FS Federation Service machines. &lt;/p&gt;
&lt;p&gt;In AD FS 2.0 RC, after IT admin installs AD FS 2 proxy server on proxy machine, she runs proxy configuration wizard (PCW) and needs to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Select or generate a certificate as the identity of the AD FS 2 proxy server. &lt;/li&gt;
&lt;li&gt;Add the certificate to AD FS Federation Service trusted proxy certificates list &lt;/li&gt;
&lt;li&gt;Outside of AD FS management console, make sure the certificate&amp;rsquo;s CA is trusted by AD FS Federation Service machines. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Such above steps are needed to set up a level of trust between AD FS proxy server and AD FS Federation Service. The AD FS proxy server might live in DMZ and provides one layer of insulation from outside attack.&lt;/p&gt;
&lt;p&gt;AD FS administrator need to keep track of the proxy identity certificate life time and proactively renew it to make sure it does not expire and disrupt its service. &lt;/p&gt;
&lt;p&gt;There are several pain points around AD FS proxy setup and maintaining experience for AD FS 2 RC version:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Setting up proxy involves touching multiple machines (both proxy and Federation Service machines) &lt;/li&gt;
&lt;li&gt;Maintaining AD FS proxy working state involves manual attention and steps &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In RTW, above issues are addressed by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Easy provisioning&lt;/i&gt;&lt;/b&gt;: AD FS admin set up proxy with AD FS Federation Service by specifying username/password of an account that is authorized by AD FS Federation Service to issue &lt;i&gt;proxy trust token&lt;/i&gt; to identify AD FS proxy servers. The p&lt;i&gt;roxy trust token &lt;/i&gt;is a form of identity issued by the AD FS Federation Service to the AD FS proxy server to identify established trust. By default, domain accounts which are part of the Administrators group on the AD FS Federation Service machines or the AD FS Federation Service domain service account are granted such privilege to provision trust by proxy from AD FS Federation Service. Such privilege is expressed via access control policy and is configurable via powershell. By default proxy trust token is valid for 15 days. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Maintenance free&lt;/i&gt;&lt;/b&gt;: Over time, the AD FS proxy server periodically renews the proxy trust token from the AD FS Federation Service to maintain AD FS proxy server in a working state. By default AD FS proxy server tries to renew proxy trust token every 4 hours. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Revocation support: &lt;/i&gt;&lt;/b&gt;If for whatever reasons, established proxy trust needs to be revoked by AD FS Federation Service, AD FS Federation Service has both powershell and UI support to do that. All proxies are revoked at the same time. There is no support for individual proxy server revocation.&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt; &lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;Repair support: &lt;/i&gt;&lt;/b&gt;When proxy trust expires or is revoked, AD FS administrator can repair such trust between AD FS proxy server and AD FS Federation Service by running PCW in UI mode or command line mode (&lt;i&gt;fspconfigwizard.exe)&lt;/i&gt;. &lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Management support&lt;/h3&gt;
&lt;p&gt;Several management aspects are involved in the new trust mechanism.&amp;nbsp; Events are added to proxy server for:&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AD FS proxy is set up correctly with AD FS Federation Service&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt; &lt;/li&gt;
&lt;li&gt;AD FS proxy server has renewed trust with AD FS Federation Service&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt; &lt;/li&gt;
&lt;li&gt;AD FS proxy failed to talk to Federation Service due to expired or invalid trust&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt; &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Events are added to Federation Service server for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AD FS proxy trust is established from a proxy machine &lt;/li&gt;
&lt;li&gt;AD FS proxy trust is renewed from a proxy machine &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Generic authorization event will be logged when:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Some party tries to establish or renew proxy trust using invalid credentials. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Proxy trust token issuance is audited just as any other issued token when AD FS audit is turned on. There are several knobs to turn to configure various proxy trust parameters:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AD FS proxy trust token lifetime &lt;/li&gt;
&lt;li&gt;AD FS proxy trust renew frequency &lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;Work flow&lt;/h1&gt;
&lt;h5&gt;Provisioning&lt;/h5&gt;
&lt;p&gt;The following picture shows AD FS admin running PCW and setting up trust from proxy server to Federation Service. &lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[3].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/1018.Image1.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The following screen shows that trust is established from proxy server to AD FS Federation Service. &lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[11].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/8345.Image2.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;From event log on proxy machine, you can see proxy server has successfully established trust with AD FS Federation Service. &lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[15].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/4810.Image3.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;On the Federation Service machine, you will see following related events.&lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[19].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/5270.Image4.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(Note: There are two 395 events created corresponding to provisioning of &lt;i&gt;one&lt;/i&gt; proxy machine. It is a side effect of PCW validating user name and password and establishing trust at the end of the wizard.)&lt;/p&gt;
&lt;h5&gt;Proxy server automatic trust renewal &lt;/h5&gt;
&lt;p&gt;Proxy server automatically renews trust with AD FS Federation Service. When that happens, you will see following event in event log on proxy machine.&lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[23].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/0363.Image5.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;h5&gt;Revocation&lt;/h5&gt;
&lt;p&gt;When a proxy server is compromised, the administrator of the AD FS Federation Service needs to revoke trust for all proxy machines. The following picture shows how AD FS admin could do it from UI. After proxy trusts are revoked, all proxy machines need to provision again to gain access to AD FS Federation Service.&lt;/p&gt;
&lt;p&gt;&lt;a href="file:///C:/Users/mattstee/AppData/Local/Temp/WindowsLiveWriter1286139640/supfiles5B00D75/image[27].png"&gt;&lt;/a&gt;&lt;img src="http://blogs.msdn.com/resized-image.ashx/__size/550x0/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-91-54/1016.Image6.png" border="0" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;h5&gt;Related powershell cmdlets&lt;/h5&gt;
&lt;p&gt;Several PowerShell cmdlets have been updated to provide PowerShell management of this new functionality:&lt;/p&gt;
&lt;p&gt;On the proxy machine:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Get-ADFSProperties, Set-ADFSProperties: (ProxyTrustRenewPeriod) get or set how often proxy server renew proxy trust with AD FS Federation Service&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;On the Federation Service machine:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Get-ADFSProperties, Set-ADFSProperties: (AddProxyAuthorizationRules, ProxyTrustTokenLifeTime): as property names suggest. &lt;/p&gt;
&lt;p&gt;Revoke-ADFSProxyTrust: revoke issued proxy trust. Proxy machines need to provision again to gain access to AD FS Federation Service.&lt;/p&gt;
&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10019012" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Announcing the RTW of Federation Extensions for SharePoint 3.0 !!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/06/01/announcing-the-rtw-of-federation-extensions-for-sharepoint-3-0.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/06/01/announcing-the-rtw-of-federation-extensions-for-sharepoint-3-0.aspx</id><published>2010-06-01T17:11:29Z</published><updated>2010-06-01T17:11:29Z</updated><content type="html">&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;It is our pleasure to announce the general availability of Federation Extensions for SharePoint 3.0 package today. This package &lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;enables federation for existing SharePoint 3.0 deployments, both Windows SharePoint Services (WSS) 3.0 and Microsoft Office SharePoint Services (MOSS) 2007. Using this package, enterprise SharePoint administrators can configure their deployments to trust any WS-Federation STS, such as &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/b/card/archive/2010/05/05/ad-fs-2-0-is-here.aspx"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;AD FS 2.0&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;, so that an enterprise can offer their services to federation partners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;The setup package of Federation Extensions for SharePoint 3.0 can be downloaded from &lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8e7b6d99-991e-44fc-a74e-9adb152ddc37&amp;amp;displaylang=en"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;This package is available in the following 24 languages:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Arabic, Chinese (Simplified), Chinese (Traditional), Czech, Danish, Dutch, English, Finnish, French, German, Greek, Hebrew, Hungarian, Italian, Japanese, Korean, Norwegian, Polish, Portuguese (Brazil), Portuguese (Portugal), Russian, Spanish, Swedish, Turkish&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;Here are the additional resources that are helpful to you:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;1.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ff646913(v=MSDN.10).aspx"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Product ReadMe for Federation Extensions for SharePoint 3.0 package&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; background: white; mso-list: l0 level1 lfo1; mso-line-height-alt: 10.5pt;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;2.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;familyid=ca9efab1-aa5d-49f5-a8da-819f6cc50a41"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Step by Step Guide&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt; and &lt;/span&gt;&lt;/span&gt;&lt;a href="https://connect.microsoft.com/site642/Downloads"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;VMs&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; for Federated Document Collaboration Using MOSS 2007 and AD FS 2.0 &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; background: white; mso-list: l0 level1 lfo1; mso-line-height-alt: 10.5pt;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;3.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ff631096(WS.10).aspx"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;AD FS 2.0 Getting Started Guide&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; background: white; mso-list: l0 level1 lfo1; mso-line-height-alt: 10.5pt;"&gt;&lt;span style="font-family: 'Segoe UI','sans-serif'; color: #333333; font-size: 9pt; mso-fareast-font-family: 'Segoe UI';"&gt;&lt;span style="mso-list: Ignore;"&gt;4.&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;AD FS 2.0 &lt;/span&gt;&lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=148500"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Design&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #1f497d; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;, &lt;/span&gt;&lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=148501"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;Deployment&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;, and &lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/adfs2-troubleshooting-guide(WS.10).aspx"&gt;&lt;span style="font-family: 'Segoe UI','sans-serif'; font-size: 9pt;"&gt;&lt;span style="color: #0000ff;"&gt;Troubleshooting&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt; Guides&lt;/span&gt;&lt;span style="font-family: 'Segoe UI','sans-serif'; color: #333333; font-size: 9pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol start="5" type="1"&gt;
&lt;li class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"&gt;&lt;a href="http://download.microsoft.com/download/7/D/0/7D0B5166-6A8A-418A-ADDD-95EE9B046994/WindowsIdentityFoundationWhitepaperForDevelopers-RTW.pdf"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;Windows Identity Foundation Whitepaper For Developers&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt; &amp;ndash; by Keith Brown &amp;amp; Sesha Mani&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p class="MsoListParagraph" style="text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1;"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;6.&lt;/span&gt;&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ff423674.aspx"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; color: #0000ff; font-size: small;"&gt;A guide to claims-based identity&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt; &amp;ndash; by Patterns &amp;amp; Practices Team&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;If you have questions, don&amp;rsquo;t hesitate to hop on the &lt;/span&gt;&lt;/span&gt;&lt;a href="http://social.msdn.microsoft.com/Forums/en/Geneva/threads"&gt;&lt;span style="color: blue; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="font-family: Calibri; font-size: small;"&gt;forum&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt; and ask.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="color: black; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;See how easy it is to enable federation for your SharePoint 3.0 applications by deploying this package today!&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Calibri;"&gt;WIF Product Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10018326" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="Geneva" scheme="http://blogs.msdn.com/b/card/archive/tags/Geneva/" /><category term="Framework" scheme="http://blogs.msdn.com/b/card/archive/tags/Framework/" /><category term="Sharepoint" scheme="http://blogs.msdn.com/b/card/archive/tags/Sharepoint/" /></entry><entry><title>Announcing the Windows Identity Foundation SDK 4.0 targeting Visual Studio 2010!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/05/11/announcing-the-windows-identity-foundation-sdk-4-0-targeting-visual-studio-2010.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/05/11/announcing-the-windows-identity-foundation-sdk-4-0-targeting-visual-studio-2010.aspx</id><published>2010-05-11T15:03:00Z</published><updated>2010-05-11T15:03:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;It is our pleasure to announce the availability of Windows Identity Foundation SDK 4.0 package, which is tailored for .NET Framework 4.0 and Visual Studio 2010. We heard your feedback on the necessity for out of the box WIF templates that work with Visual Studio 2010 and samples that work with .NET Framework 4.0. This package addresses these two requests.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;You can download the WIF SDK 4.0 setup package from &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c148b2df-c7af-46bb-9162-2c9422208504"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/B&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Note that this package is only available in US-English language. Localized versions of this package will be delivered later.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Here are the additional resources that are helpful to you:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;OL type=1&gt;
&lt;LI style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt; mso-list: l1 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;A href="http://download.microsoft.com/download/7/D/0/7D0B5166-6A8A-418A-ADDD-95EE9B046994/WindowsIdentityFoundationWhitepaperForDevelopers-RTW.pdf"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;WIF Whitepaper For Developers&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; – by Keith Brown &amp;amp; Sesha Mani&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3 face=Calibri&gt;New release of the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=c3e315fa-94e2-4028-99cb-904369f177c0" target=_blank&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3 face=Calibri&gt;Identity Developer Training Kit&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: black; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; – by DPE Team&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/ee748484.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3 face=Calibri&gt;WIF Product Documentation on MSDN&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; – by WIF User Assistance Team&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/ff423674.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT size=3 face=Calibri&gt;A guide to claims-based identity&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; – by Patterns &amp;amp; Practices Team&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Enjoy coding with WIF!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;WIF Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 13pt"&gt;&lt;FONT face=Calibri&gt;Announcing the localization support for WIF SDK 3.5!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;We are glad to announce the complete localization support for Windows Identity Foundation SDK 3.5 today. Following are the languages we have localized the SDK to:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;French (fr-FR)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;German (de-DE)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Japanese (ja-JP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Spanish (es-ES)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Italian (it-IT)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;6.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Russian (ru-RU)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;7.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Chinese-Simplified (zh-CN)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;8.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Chinese-Traditional (zh-TW)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;9.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Korean (ko-KO)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;You can obtain the localized WIF SDK setup packages from &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c148b2df-c7af-46bb-9162-2c9422208504"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Happy coding with WIF!!!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;WIF Team&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10011004" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term=".NET 3.5" scheme="http://blogs.msdn.com/b/card/archive/tags/-NET+3-5/" /><category term="Framework" scheme="http://blogs.msdn.com/b/card/archive/tags/Framework/" /><category term="Visual Studio" scheme="http://blogs.msdn.com/b/card/archive/tags/Visual+Studio/" /><category term="SDK" scheme="http://blogs.msdn.com/b/card/archive/tags/SDK/" /><category term=".NET 4.0" scheme="http://blogs.msdn.com/b/card/archive/tags/-NET+4-0/" /><category term="RTW" scheme="http://blogs.msdn.com/b/card/archive/tags/RTW/" /></entry><entry><title>AD FS 2.0 is here!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/05/05/ad-fs-2-0-is-here.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/05/05/ad-fs-2-0-is-here.aspx</id><published>2010-05-05T16:38:00Z</published><updated>2010-05-05T16:38:00Z</updated><content type="html">&lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;We are very happy to announce the general availability of AD FS 2.0!&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;It is our pleasure to offer this release for Windows Server 2008 and 2008 R2 that makes it easier to work across companies, leverage the cloud, and develop secure applications all while using industry standard interoperable protocols. We listened to your feedback from the release candidate and have made AD FS 2.0 even easier to manage by simplifying proxy management.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Finally, we’ve hammered this build to ensure you’ll see the rock solid reliability and screaming fast performance that you’d expect from Microsoft.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;The setup package for AD FS 2.0 can be downloaded &lt;/font&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=118c3588-9070-426a-b655-6cec0a92c10b" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=118c3588-9070-426a-b655-6cec0a92c10b"&gt;&lt;span style="font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;here&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;The team behind making AD FS 2.0 can be seen in several &lt;/font&gt;&lt;/span&gt;&lt;a href="http://channel9.msdn.com/identity/" mce_href="http://channel9.msdn.com/identity/"&gt;&lt;span style="font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font color="#0000ff" face="Calibri"&gt;Channel 9 videos&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;font face="Calibri"&gt;&lt;span style="color: #1f497d; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt; &lt;/span&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;discussing the features and capabilities of the release.&lt;/span&gt;&lt;span style="color: #1f497d; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;        &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;Check out the following resources to learn more about AD FS 2.0:        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.5in; mso-list: l0 level1 lfo1" class="MsoListParagraph"&gt;&lt;span style="font-family: symbol; color: black; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt;Our official &lt;/font&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/windowsserver2008/en/us/ad-fs-2-overview.aspx" target="_blank" mce_href="http://www.microsoft.com/windowsserver2008/en/us/ad-fs-2-overview.aspx"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-fareast-font-family: calibri"&gt;&lt;font size="3"&gt;website&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;u&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: blue; mso-fareast-font-family: calibri"&gt; &lt;/span&gt;&lt;/u&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.5in; mso-list: l0 level1 lfo1" class="MsoListParagraph"&gt;&lt;span style="font-family: symbol; color: black; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ff631096(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/ff631096(WS.10).aspx"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;AD FS 2.0 Getting Started Guide&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: #1f497d"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto auto auto 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: symbol; color: black; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;familyid=ca9efab1-aa5d-49f5-a8da-819f6cc50a41" mce_href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;familyid=ca9efab1-aa5d-49f5-a8da-819f6cc50a41"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;Step by Step Guide&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt; and &lt;/font&gt;&lt;/span&gt;&lt;a href="https://connect.microsoft.com/site642/Downloads" mce_href="https://connect.microsoft.com/site642/Downloads"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;VMs&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt; for Federated Document Collaboration Using MOSS 2007 and AD FS 2.0        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto auto auto 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: symbol; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt;AD FS 2.0 &lt;/font&gt;&lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=148500" mce_href="http://go.microsoft.com/fwlink/?LinkID=148500"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;Design&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: #1f497d"&gt;&lt;font size="3"&gt;, &lt;/font&gt;&lt;/span&gt;&lt;a href="http://go.microsoft.com/fwlink/?LinkID=148501" mce_href="http://go.microsoft.com/fwlink/?LinkID=148501"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;Deployment&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt;, and &lt;/font&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/adfs2-troubleshooting-guide(WS.10).aspx"&gt;Troubleshooting&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;&lt;/font&gt;&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt; Guides&lt;/span&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto auto auto 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: symbol; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/ee895355.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ee895355.aspx"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font size="3"&gt;AD FS 2.0 developer documentation&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt;&lt;font size="3"&gt; and &lt;/font&gt;&lt;/span&gt;&lt;a href="http://technet.microsoft.com/en-us/library/ee892329.aspx" mce_href="http://technet.microsoft.com/en-us/library/ee892329.aspx"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;PowerShell reference&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;    &lt;p&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto auto auto 0.5in; mso-list: l0 level1 lfo1; mso-add-space: auto" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: symbol; mso-bidi-font-family: symbol; mso-fareast-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://blogs.msdn.com/card/archive/2009/11/18/windows-identity-foundation-wif-rtm-announced.aspx" mce_href="http://blogs.msdn.com/card/archive/2009/11/18/windows-identity-foundation-wif-rtm-announced.aspx"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;font color="#0000ff" size="3"&gt;Resources&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;span style="font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black"&gt; for developing claims based applications with Windows Identity Foundation (WIF)&lt;/span&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;We’d like to give a big thank you to everyone who’s helped us by providing feedback since we had our first Beta.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Stay tuned here as we will continue&lt;/span&gt;&lt;span style="color: #1f497d; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt; &lt;/span&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;to blog about AD FS 2.0 features over the coming weeks and months.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;If you have questions, don’t hesitate to hop on the &lt;/span&gt;&lt;/font&gt;&lt;a href="http://social.msdn.microsoft.com/Forums/en/Geneva/threads" mce_href="http://social.msdn.microsoft.com/Forums/en/Geneva/threads"&gt;&lt;span style="font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font color="#0000ff" face="Calibri"&gt;forum&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt; and ask.       &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;See how you can use claims to unleash the power of your identity infrastructure by deploying AD FS 2.0 today!&lt;/span&gt;&lt;span style="font-family: &amp;#39;Times New Roman&amp;#39;,&amp;#39;serif&amp;#39;; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-theme-font: minor-latin"&gt;       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="line-height: normal; margin: 0in 0in 10pt" class="MsoNormal"&gt;&lt;span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;font face="Calibri"&gt;The AD FS 2.0 Product Team       &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10007886" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Update on Windows CardSpace</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/b/card/archive/2010/04/27/update-on-windows-cardspace.aspx" /><id>http://blogs.msdn.com/b/card/archive/2010/04/27/update-on-windows-cardspace.aspx</id><published>2010-04-27T15:55:00Z</published><updated>2010-04-27T15:55:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 12pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt"&gt;We have decided to postpone the release of Windows CardSpace 2.0. &amp;nbsp;&amp;nbsp;This is due to a number of recent and exciting developments in technologies such as U-Prove and Open ID that can be used for Information Cards and other user-centric identity applications.&amp;nbsp; We are postponing the release to get additional customer feedback and engage with the industry on these technologies.&amp;nbsp;&amp;nbsp;We will communicate additional details at a later time. &lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 12pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt"&gt;As part of our continued investment in these areas, we will deliver a Community Technology Preview in Q2 2010 that will enable the soon-to-be-released Active Directory Federation Services 2.0 (AD FS 2.0) in Windows Server to issue Information Cards.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 12pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; FONT-SIZE: 7pt"&gt;&lt;FONT face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: black; FONT-SIZE: 11pt"&gt;Microsoft remains committed in the development of digital identity technologies, interoperable identity standards, the claims-based identity model, and Information Cards.&amp;nbsp; AD FS 2.0 is on track for release&amp;nbsp; shortly.&amp;nbsp; We also continue to actively participate in industry groups such as the Information Card Foundation, the OpenID Foundation, and standards bodies such as OASIS.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10003271" width="1" height="1"&gt;</content><author><name>CardSpaceBlog</name><uri>http://blogs.msdn.com/CardSpaceBlog/ProfileUrlRedirect.ashx</uri></author><category term="CardSpace" scheme="http://blogs.msdn.com/b/card/archive/tags/CardSpace/" /><category term="U-Prove" scheme="http://blogs.msdn.com/b/card/archive/tags/U_2D00_Prove/" /></entry></feed>
