AD FS allows the sharing of identities between trusted business partners (federated) with minimum identity infrastructure changes. AD FS 2016 added many new features to protect federated environments from rising identity infrastructure threats. In Chapter 13, Active Directory Federation Services, I will explain AD FS in detail. Right now, I am going to summarize the shiny new features it has.
In the previous section about Microsoft Passport, I explained why the traditional username/password method is no longer an option against modern identity threats. This is applicable to federated environments as well. Most federated environments use MFA as another layer of security. AD FS 2016 supports three new methods to authenticate without usernames and passwords.
Microsoft Azure provides Azure MFA as a service to protect cloud workloads from unauthorized access. If...