Select the Optimal Resource Account Option
Applies To: Windows Server 2008
Active Directory Federation Services (AD FS) provides controls that the resource administrator—that is, the AD FS administrator in the resource partner forest—can use to define how resource accounts are used for a particular account partner. The following table describes resource account options and the circumstances in which a resource administrator might use them.
Resource account option | Description | Can be used when the resource administrator wants to … |
---|---|---|
Resource accounts exist for all users |
Specifies that a resource account is configured for each user from the account partner that needs access to the resource. In this case, incoming group claims are not mapped to resource groups even if resource groups are configured. |
|
Resource accounts exist for some users (prefer resource account) |
Specifies that resource groups are used for some user accounts. This means that some users may have individual resource accounts created for them, while other users may be configured to use resource groups. When you select this option, AD FS first looks for resource accounts that match the user principal name (UPN) claim or e-mail claim that is specified in the incoming token. AD FS uses these resource accounts if they exist. Otherwise, if the token has a group claim that is mapped to a resource group, AD FS uses the resource group. |
|
Resource accounts exist for some users (prefer groups in token) |
This is the default setting. Specifies that AD FS can use its logic to determine if each incoming token maps to a resource group or if it looks for a resource account. When this option is selected, AD FS first looks in the token for incoming group claims that it can map to a resource group. If AD FS finds the incoming group claims, it uses the resource group. If there is no incoming group claim, AD FS looks for a resource account to use. |
|
No resource accounts exist for this account partner |
Specifies that one or more resource groups will be used for all users in this account partner. This means that every token that is issued from this account partner will be required to contain one or more group claims that map to one or more resource groups in the resource partner forest. |
|
For more information about how you can modify these resource account options, see Configure Resource Account Options.
Comparing resource account options
Before you select any other option besides the default option, compare the various advantages and disadvantages that can result from using another resource account option, as described in the following table.
Resource account option | Advantages | Disadvantages |
---|---|---|
Resource accounts exist for all users |
|
|
Resource accounts exist for some users (prefer resource account) |
|
|
Resource accounts exist for some users (prefer groups in token) |
|
|
No resource accounts exist for this account partner |
|
|