WS-Federation

FoxIDs supports WS-Federation as both an authentication method and an application registration.

FoxIDs WS-Federation

WS-Federation is an XML-based identity federation protocol used by enterprise and legacy web applications. It is commonly used with AD FS, Microsoft Entra ID legacy WS-Federation applications, SharePoint, Dynamics, and older ASP.NET applications.

FoxIDs supports WS-Federation passive sign-in, WS-Federation sign-out, Federation Metadata import and export, Microsoft Entra ID Windows sign-in endpoints, and SAML token types used by WS-Federation.

Authentication method

Configure a WS-Federation authentication method that trusts an external WS-Federation Security Token Service (STS) / Identity Provider (IdP).

FoxIDs acts as the WS-Federation relying party when users are sent to the external STS. The external STS returns a SAML token in the WS-Federation response, and FoxIDs converts the claims internally to JWT claims before issuing tokens or assertions to the application registration.

Typical identity providers include AD FS, Microsoft Entra ID legacy WS-Federation applications, SharePoint, Dynamics, and generic WS-Federation STSes.

Application registration

Configure your application as a WS-Federation application registration.

Your application becomes a WS-Federation relying party, and FoxIDs acts as the Security Token Service (STS). FoxIDs exposes Federation Metadata to the application and issues SAML tokens in WS-Federation sign-in responses.

Typical relying parties include Microsoft Entra ID domain federation, Microsoft Entra joined and Microsoft Entra hybrid joined Windows devices, AD FS relying party trusts, SharePoint, Dynamics, older ASP.NET WS-Federation middleware, and generic WS-Federation applications.

Microsoft Entra ID Windows sign-in

Microsoft Entra ID Windows sign-in can be enabled on a WS-Federation application registration when FoxIDs is used as the federated identity provider for a Microsoft Entra ID domain. It supports federated Windows sign-in for Microsoft Entra joined and Microsoft Entra hybrid joined devices. FoxIDs does not join or register devices; device registration is handled by Microsoft Entra ID and Windows.

When Microsoft Entra ID Windows sign-in is enabled, FoxIDs exposes MEX, the active WS-Trust 1.3 username mixed endpoint, and uses the application-specific issuer for the registration. A custom IdP issuer is ignored while it is enabled. Enable it only for Microsoft Entra ID and Windows clients that require active WS-Trust behaviour, and make sure exactly one compatible login authentication method is allowed.

Password reset through Ctrl+Alt+Del is Windows device behaviour. It does not work on devices that are only Microsoft Entra joined and not joined to a local Active Directory domain. Use browser-based password reset or passwordless flows for those devices. Microsoft Entra hybrid joined or local domain joined devices can continue to use the domain password change and reset experience.

How-to guides:

Token types

WS-Federation in FoxIDs can issue and validate:

  • SAML 1.1
  • SAML 2.0

SAML 1.1 is the default token type because it is widely used by WS-Federation systems such as AD FS. SAML 1.x metadata token type aliases are treated as SAML 1.1. The token type can be configured for both authentication methods and application registrations.

Claim mappings

WS-Federation tokens contain SAML claims. FoxIDs converts SAML claims to JWT claims internally between the authentication method and the application registration.

The SAML/JWT claim mappings are shared with SAML 2.0 and can be configured in the settings menu in FoxIDs Control.

Your Privacy

Your Privacy

We use cookies to make your experience of our websites better. Click the 'Accept all cookies' button to agree to the use of cookies. To opt out of non-essential cookies, click 'Necessary cookies only'.

Visit our Privacy Policy page for more