As you may already know, update Rollup 1 for AD FS 2.0 is available. Big news if you’re an Office 365 user:
- Multiple Issuer support (support for multiple UPN suffixes thus remedying issues described below)
It’s all described here:
http://support.microsoft.com/kb/2607496
What is not obvious from the above document is how one actually goes about setting up multiple domains. To work that one out you’ll need to read this post.
http://community.office365.com/en-us/w/sso/support-for-multiple-top-level-domains.aspx
In short, plan for this! The relying party for the Microsoft Online Identity Platform will need to be deleted, the federation trust for the existing AD FS realm updated with the –SupportMultipleDomain option, thus allowing support for (further) issuer/domain suffixes.
Thanks to Ross Adams from MSFT for the tip… this one had me scratching my head