Active Directory Federation Services provides access control and single sign on (SSO) across a wide variety of applications including Amazon WorkMail, Amazon WorkSpaces, Amazon WorkDocs, Office 365, cloud based SaaS applications, and applications on the corporate network.
For the user, it provides seamless sign on using the same, familiar account credentials.
For the developer, it provides an easy way to authenticate users whose identities live in the organizational directory so that you can focus your efforts on your application, not authentication or identity.
Eliminate Passwords from the Extranet
Sign in with AWS Multi-Factor Authentication
Password-less Access from Compliant Devices
Sign in with Windows Hello for Business
Secure Access to Applications
Modern Authentication
Configure access control policies without having to know claim rules language
Enable sign on with non-AD LDAP directories
Better Sign-in experience
Customize sign in experience for AD FS applications
Manageability and Operational Enhancements
Streamlined auditing for easier administrative management
Improved interoperability with SAML 2.0 for participation in confederations
Simplified password management for federated users
Highlights
Provide single sign on (SSO) across a wide variety of applications including Amazon WorkMail, Amazon WorkSpaces, Amazon WorkDocs, Office 365, cloud based SaaS applications and applications on the corporate network.
Provide AWS Multi-Factor Authentication to your users when signing into federated applications
Provide sign on and access control to both modern and legacy applications, on premises and in the cloud, based on the same set of credentials and policies.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for a Windows Server 2019 image preconfigured with Active Directory Federation Services. Pricing runs on top of your chosen EC2 instance type, and each instance type is its own dimension billed per hour. There are no tiers or plans to select. Instead, you match pricing to compute size. Smaller instances (such as t3 and t2 sizes) carry lower hourly rates, while memory-, compute-, storage-, and GPU-focused families (such as r5, c5, i3, x1e, and p3) scale up in capacity and cost. Your total hourly cost combines the software rate with your instance's compute charge.
Top-of-mind questions for buyers
What does one hourly unit cover, and what runs on the instance I pick?
One unit is one running EC2 instance of your chosen type, billed per hour. Each instance runs a Windows Server 2019 image preconfigured with Active Directory Federation Services. You can also deploy an optional Web Application Proxy server for publishing applications. The instance type you select sets the CPU, memory, and storage available.
Am I charged when the ADFS instance is stopped or powered off?
Software charges meter running time by the hour. A fully stopped instance does not accrue hourly software charges. Stopped instances may still incur underlying AWS storage fees for their attached volumes. Charges resume when you restart the instance. There is no upfront commitment, so cost tracks actual running hours.
How does my total hourly cost combine, and which part changes when I resize?
Two charges bill together on one invoice: the software rate and the AWS compute charge for your instance type. They add up per running hour. When you move to a bigger family such as r5, i3, x1e, or p3, the compute charge rises with capacity. Smaller t2 or t3 sizes carry lower compute charges.
cloudinfrastructureservices.co.uk+1
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Latest OS patches installed. Simply run Windows update to install latest Microsoft OS patches.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Enables seamless single sign-on across multiple applications including Amazon WorkMail, Amazon WorkSpaces, Amazon WorkDocs, Office 365, cloud-based SaaS applications, and corporate network applications using organizational directory credentials.
Multi-Factor Authentication Integration
Supports AWS Multi-Factor Authentication for enhanced security when users sign into federated applications.
Modern Authentication Support
Implements modern authentication mechanisms including Windows Hello for Business, password-less access from compliant devices, and SAML 2.0 protocol support for federation participation.
Access Control and Policy Management
Provides configurable access control policies for both modern and legacy applications without requiring knowledge of claim rules language, with support for non-AD LDAP directory integration.
Pre-configured Server Environment
Includes pre-loaded ADFS role, ADFS PowerShell module, and all prerequisite components on Windows Server 2019 for rapid deployment.
Cloud Directory Identity Management
Centralize access across all identities with integrations to AWS Identity Center, Google Workspace, Microsoft 365, Active Directory, HRIS platforms, and network infrastructure resources
Single Sign-On and Multi-Factor Authentication
Frictionless, secure access to AWS resources and over 900 pre-built applications with automated user provisioning to Amazon IAM Identity Center and group-based permissions
Cross-Operating System Server and Device Management
Deploy, manage, and remotely assist AWS servers and corporate devices across Windows, macOS, iOS, Linux, AWS Linux AMIs, and Android from a single cloud platform
Passwordless and Conditional Access
Enable phishing-resistant access with passwordless SSO, password management, and conditional access controls to ensure only specific users on trusted devices and networks can access AWS resources
Unified Platform with Zero Trust Capabilities
Combine cloud directory identity management, access management, and cross-OS server and device management with enhanced IAM and device management controls to support Zero Trust security goals
Single Sign-On (SSO)
Automatically synchronizes users across multiple directories to enable one-click access to corporate applications on-premises and in the cloud with enforced security policies and self-service password reset capabilities.
Multi-Factor Authentication (MFA)
Supports multiple authentication methods including passwordless authentication, passkeys, one-time passcodes, push notifications, biometric data, and security keys with real-time reporting and monitoring of authentication events.
Adaptive Authentication
Delivers multi-layer, context-aware and risk-based protection to minimize common attacks and enforce contextual access security policies based on user behavior and risk assessment.
Identity Lifecycle Management
Provides role-based user provisioning engine with granular access permissions, least-privileged access controls, and automated user account provisioning across applications and AWS services.
Directory Integration
Acts as a secure cloud-based directory with integration capabilities for Active Directory, LDAP, G Suite and other external directories, plus pre-built connectors with thousands of third-party web applications and AWS services including AWS IAM, AWS SSO, Amazon Cognito, and Amazon EventBridge.
managing this software is a giant pain and is frustrating
What problems is the product solving and how is that benefiting you?
do authenticactions in a federated environment
Varun D.
Beyond ADFS: Exploring Alternative for Seamless Single Sign-On
Reviewed on Apr 02, 2024
Review provided by G2
What do you like best about the product?
Securities Features makes ADFS server 2019 a valuable tool for organisations looking to strengthen their identity and access management strategies and protect against security threats.
What do you dislike about the product?
Complexity and resource requirements may pose challenges for some users, particularly smaller organisations or limited IT expertise in identity management.
What problems is the product solving and how is that benefiting you?
ADFS Server 2019 makes managing user identities easier by offering seamless single Sign-On, secure identity sharing, and easy compliance auditing.
Pawan K.
Use ADFS Server Windows 2019 to integrate your applications with single sign on
Reviewed on Mar 10, 2024
Review provided by G2
What do you like best about the product?
Using ADFS servers, we were able to integrate our SAML/Auth/WS-Fed based applications. It works seamless to enable our users to use SSO.
What do you dislike about the product?
It is again a bit complex when coming to sending custom claims.
What problems is the product solving and how is that benefiting you?
It has enabled our inhouse and thirdparty applications to facilitate the single signon. It enabled to grant access to applications based on organisational policies and segerate the authorisation based on network type.
Saurabh S.
Single sign on with ADFS
Reviewed on Mar 04, 2024
Review provided by G2
What do you like best about the product?
Most useful feature is that ADFS provides Single Sign On (SSO) with application/web portal. We can create multiple reply party trust with metadata files to onboarding OnPrem application for authentication.
What do you dislike about the product?
It doesn't support Azure MFA or any 3rd party MfA
What problems is the product solving and how is that benefiting you?
Integration of any application for authentication was really big challenge. now for resolved by using ADFS services with multiple factor authentication.
Higher Education
A successful update from 2016 to 2019
Reviewed on Aug 05, 2022
Review provided by G2
What do you like best about the product?
ADFS account lockout feature is the reason we upgraded from 2016 to 2019. In 1 month period test running, there were 28 successful updates and 2 failures
What do you dislike about the product?
sometimes when trying to add relying party trust, the configure failed to apply
What problems is the product solving and how is that benefiting you?
Using extranet lockout feature, users could be managed in more efficient way