Tuesday, November 03, 2015

ADFS : whr for AD

You can use whr to tell ADFS what CP to use which saves ADFS from asking the user via HRD.

So if you had some kind of IDP upstream whose ID was "urn:idp:auth", then setting the whr to that value tells ADFS to find the IDP with that ID and redirect to it seamlessly.

That's fine when you have another CP but what if you want to force ADFS to choose the local AD?

What's AD's ID?

After consulting with Mr. Google, the answer is the address of the ADFS service i.e.



