You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-provisioning/how-to-prerequisites.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -48,7 +48,7 @@ Run the [IdFix tool](https://docs.microsoft.com/office365/enterprise/prepare-dir
48
48
49
49
| Port number | How it's used |
50
50
| --- | --- |
51
-
|**80**| Downloads the certificate revocation lists (CRLs) while validating the SSL certificate. |
51
+
|**80**| Downloads the certificate revocation lists (CRLs) while validating the TLS/SSL certificate. |
52
52
|**443**| Handles all outbound communication with the service. |
53
53
|**8080** (optional) | Agents report their status every 10 minutes over port 8080, if port 443 is unavailable. This status is displayed in the Azure AD portal. |
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-provisioning/tutorial-existing-forest.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -38,7 +38,7 @@ In this scenario, there is an existing forest synced using Azure AD Connect sync
38
38
39
39
| Port number | How it's used |
40
40
| --- | --- |
41
-
|**80**| Downloads the certificate revocation lists (CRLs) while validating the SSL certificate |
41
+
|**80**| Downloads the certificate revocation lists (CRLs) while validating the TLS/SSL certificate |
42
42
|**443**| Handles all outbound communication with the service |
43
43
|**8080** (optional) | Agents report their status every 10 minutes over port 8080, if port 443 is unavailable. This status is displayed on the Azure AD portal. |
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-provisioning/tutorial-single-forest.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -36,7 +36,7 @@ You can use the environment you create in this tutorial for testing or for getti
36
36
37
37
| Port number | How it's used |
38
38
| --- | --- |
39
-
|**80**| Downloads the certificate revocation lists (CRLs) while validating the SSL certificate |
39
+
|**80**| Downloads the certificate revocation lists (CRLs) while validating the TLS/SSL certificate |
40
40
|**443**| Handles all outbound communication with the service |
41
41
|**8080** (optional) | Agents report their status every 10 minutes over port 8080, if port 443 is unavailable. This status is displayed on the Azure AD portal. |
| Add federated domain | If the domain is being added for the first time, that is, the setup is changing from single domain federation to multi-domain federation – Azure AD Connect will recreate the trust from scratch. If the trust with Azure AD is already configured for multiple domains, only Issuance transform rules are modified |
61
-
| Update SSL| None |
61
+
| Update TLS| None |
62
62
63
63
During all operations, in which, any setting is modified, Azure AD Connect makes a backup of the current trust settings at **%ProgramData%\AADConnect\ADFS**
5. On the **AD FS Servers** page, enter the server name or IP address to be added to the AD FS farm.
109
109
@@ -131,7 +131,7 @@ Configuring alternate login ID for AD FS consists of two main steps:
131
131
3. On the **Specify SSL certificate** page, provide the password for the PFX file that you provided when you configured the AD FS farm with Azure AD Connect.
4. Add the server to be added as a WAP server. Because the WAP server might not be joined to the domain, the wizard asks for administrative credentials to the server being added.
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/how-to-connect-fed-ssl-update.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Azure AD Connect - Update the SSL certificate for an AD FS farm | Microsoft Docs
3
-
description: This document details the steps to update the SSL certificate of an AD FS farm by using Azure AD Connect.
2
+
title: Azure AD Connect - Update the TLS/SSL certificate for an AD FS farm | Microsoft Docs
3
+
description: This document details the steps to update the TLS/SSL certificate of an AD FS farm by using Azure AD Connect.
4
4
services: active-directory
5
5
manager: daveba
6
6
editor: billmath
@@ -18,12 +18,12 @@ ms.author: billmath
18
18
ms.collection: M365-identity-device-management
19
19
---
20
20
21
-
# Update the SSL certificate for an Active Directory Federation Services (AD FS) farm
21
+
# Update the TLS/SSL certificate for an Active Directory Federation Services (AD FS) farm
22
22
23
23
## Overview
24
-
This article describes how you can use Azure AD Connect to update the SSL certificate for an Active Directory Federation Services (AD FS) farm. You can use the Azure AD Connect tool to easily update the SSL certificate for the AD FS farm even if the user sign-in method selected is not AD FS.
24
+
This article describes how you can use Azure AD Connect to update the TLS/SSL certificate for an Active Directory Federation Services (AD FS) farm. You can use the Azure AD Connect tool to easily update the TLS/SSL certificate for the AD FS farm even if the user sign-in method selected is not AD FS.
25
25
26
-
You can perform the whole operation of updating SSL certificate for the AD FS farm across all federation and Web Application Proxy (WAP) servers in three simple steps:
26
+
You can perform the whole operation of updating TLS/SSL certificate for the AD FS farm across all federation and Web Application Proxy (WAP) servers in three simple steps:
Azure AD Connect attempts to obtain information about the AD FS farm automatically by:
44
44
1. Querying the farm information from AD FS (Windows Server 2016 or later).
45
45
2. Referencing the information from previous runs, which are stored locally with Azure AD Connect.
46
46
47
-
You can modify the list of servers that are displayed by adding or removing the servers to reflect the current configuration of the AD FS farm. As soon as the server information is provided, Azure AD Connect displays the connectivity and current SSL certificate status.
47
+
You can modify the list of servers that are displayed by adding or removing the servers to reflect the current configuration of the AD FS farm. As soon as the server information is provided, Azure AD Connect displays the connectivity and current TLS/SSL certificate status.
48
48
49
49

50
50
@@ -55,11 +55,11 @@ If the list contains a server that's no longer part of the AD FS farm, click **R
55
55
>[!NOTE]
56
56
> Removing a server from the list of servers for an AD FS farm in Azure AD Connect is a local operation and updates the information for the AD FS farm that Azure AD Connect maintains locally. Azure AD Connect doesn't modify the configuration on AD FS to reflect the change.
57
57
58
-
## Step 2: Provide a new SSL certificate
58
+
## Step 2: Provide a new TLS/SSL certificate
59
59
60
-
After you've confirmed the information about AD FS farm servers, Azure AD Connect asks for the new SSL certificate. Provide a password-protected PFX certificate to continue the installation.
60
+
After you've confirmed the information about AD FS farm servers, Azure AD Connect asks for the new TLS/SSL certificate. Provide a password-protected PFX certificate to continue the installation.
After you provide the certificate, Azure AD Connect goes through a series of prerequisites. Verify the certificate to ensure that the certificate is correct for the AD FS farm:
65
65
@@ -70,7 +70,7 @@ After you provide the certificate, Azure AD Connect goes through a series of pre
70
70
71
71
## Step 3: Select servers for the update
72
72
73
-
In the next step, select the servers that need to have the SSL certificate updated. Servers that are offline can't be selected for the update.
73
+
In the next step, select the servers that need to have the TLS/SSL certificate updated. Servers that are offline can't be selected for the update.
74
74
75
75

76
76
@@ -80,7 +80,7 @@ After you complete the configuration, Azure AD Connect displays the message that
80
80
81
81
## FAQs
82
82
83
-
***What should be the subject name of the certificate for the new AD FS SSL certificate?**
83
+
***What should be the subject name of the certificate for the new AD FS TLS/SSL certificate?**
84
84
85
85
Azure AD Connect checks if the subject name/alternate subject name of the certificate contains the federation service name. For example, if your federation service name is fs.contoso.com, the subject name/alternate subject name must be fs.contoso.com. Wildcard certificates are also accepted.
86
86
@@ -92,7 +92,7 @@ After you complete the configuration, Azure AD Connect displays the message that
92
92
93
93
Azure AD Connect can't perform any operation if the server is offline. If the server is part of the AD FS farm, then check the connectivity to the server. After you've resolved the issue, press the refresh icon to update the status in the wizard. If the server was part of the farm earlier but now no longer exists, click **Remove** to delete it from the list of servers that Azure AD Connect maintains. Removing the server from the list in Azure AD Connect doesn't alter the AD FS configuration itself. If you're using AD FS in Windows Server 2016 or later, the server remains in the configuration settings and will be shown again the next time the task is run.
94
94
95
-
***Can I update a subset of my farm servers with the new SSL certificate?**
95
+
***Can I update a subset of my farm servers with the new TLS/SSL certificate?**
96
96
97
97
Yes. You can always run the task **Update SSL Certificate** again to update the remaining servers. On the **Select servers for SSL certificate update** page, you can sort the list of servers on **SSL Expiry date** to easily access the servers that aren't updated yet.
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/how-to-connect-fed-whatis.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,7 +37,7 @@ This topic is the home for information on federation-related functionalities for
37
37
|[Add a new AD FS server](how-to-connect-fed-management.md#addadfsserver)|Expand an AD FS farm with an additional AD FS server after initial installation. |
38
38
|[Add a new AD FS WAP server](how-to-connect-fed-management.md#addwapserver)|Expand an AD FS farm with an additional Web Application Proxy (WAP) server after initial installation. |
39
39
|[Add a new federated domain](how-to-connect-fed-management.md#addfeddomain)|Add another domain to be federated with Azure AD. |
40
-
|[Update the SSL certificate](how-to-connect-fed-ssl-update.md)| Update the SSL certificate for an AD FS farm. |
40
+
|[Update the TLS/SSL certificate](how-to-connect-fed-ssl-update.md)| Update the TLS/SSL certificate for an AD FS farm. |
41
41
|[Renew federation certificates for Office 365 and Azure AD](how-to-connect-fed-o365-certs.md)|Renew your O365 certificate with Azure AD.|
42
42
|**Other federation configuration**||
43
43
|[Federate multiple instances of Azure AD with single instance of AD FS](how-to-connect-fed-single-adfs-multitenant-federation.md)| Federate multiple Azure AD with single AD FS farm|
Copy file name to clipboardExpand all lines: articles/active-directory/hybrid/how-to-connect-health-agent-install.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ The following table is a list of requirements for using Azure AD Connect Health.
33
33
| Azure AD Connect Health Agent is installed on each targeted server | Azure AD Connect Health requires the Health Agents to be installed and configured on targeted servers to receive the data and provide the Monitoring and Analytics capabilities. <br /><br />For example, to get data from your AD FS infrastructure, the agent must be installed on the AD FS and Web Application Proxy servers. Similarly, to get data on your on-premises AD DS infrastructure, the agent must be installed on the domain controllers. <br /><br /> |
34
34
| Outbound connectivity to the Azure service endpoints | During installation and runtime, the agent requires connectivity to Azure AD Connect Health service endpoints. If outbound connectivity is blocked using Firewalls, ensure that the following endpoints are added to the allowed list. See [outbound connectivity endpoints](how-to-connect-health-agent-install.md#outbound-connectivity-to-the-azure-service-endpoints)|
35
35
|Outbound connectivity based on IP Addresses | For IP address based filtering on firewalls, refer to the [Azure IP Ranges](https://www.microsoft.com/download/details.aspx?id=41653).|
36
-
|SSL Inspection for outbound traffic is filtered or disabled | The agent registration step or data upload operations may fail if there is SSL inspection or termination for outbound traffic at the network layer. Read more about [how to setup SSL inspection](https://technet.microsoft.com/library/ee796230.aspx)|
36
+
|TLS Inspection for outbound traffic is filtered or disabled | The agent registration step or data upload operations may fail if there is TLS inspection or termination for outbound traffic at the network layer. Read more about [how to setup TLS inspection](https://technet.microsoft.com/library/ee796230.aspx)|
37
37
| Firewall ports on the server running the agent |The agent requires the following firewall ports to be open in order for the agent to communicate with the Azure AD Health service endpoints.<br /><br /><li>TCP port 443</li><li>TCP port 5671</li> <br />Note that port 5671 is no longer required for the latest version of agent. Upgrade to the latest version so only port 443 is required. Read more about [enable firewall ports](https://technet.microsoft.com/library/ms345310(v=sql.100).aspx)|
38
38
| Allow the following websites if IE Enhanced Security is enabled |If IE Enhanced Security is enabled, then the following websites must be allowed on the server that is going to have the agent installed.<br /><br /><li>https:\//login.microsoftonline.com</li><li>https:\//secure.aadcdn.microsoftonline-p.com</li><li>https:\//login.windows.net</li><li>https:\//aadcdn.msftauth.net</li><li>The federation server for your organization trusted by Azure Active Directory. For example: https:\//sts.contoso.com</li> Read more about [how to configure IE](https://support.microsoft.com/help/815141/internet-explorer-enhanced-security-configuration-changes-the-browsing). In case you have a proxy within your network , please see note below.|
39
39
| Ensure PowerShell v4.0 or newer is installed | <li>Windows Server 2008 R2 ships with PowerShell v2.0, which is insufficient for the agent. Update PowerShell as explained below under [Agent installation on Windows Server 2008 R2 Servers](#agent-installation-on-windows-server-2008-r2-servers).</li><li>Windows Server 2012 ships with PowerShell v3.0, which is insufficient for the agent. [Update](https://www.microsoft.com/download/details.aspx?id=40855) the Windows Management Framework.</li><li>Windows Server 2012 R2 and later ship with a sufficiently recent version of PowerShell.</li>|
0 commit comments