1

If I am a relying party, I can expose federation metadata to ease configuration for AD FS so I can import it into the Create a Relying Party Trust wizard. I can also choose to enable automatic updates so AD FS checks this file regularly. This file contains information like bindings but also certificates but I am not sure if it contains sensitive information.

My question is: Is it OK for this file to be publicly accessible to anyone besides AD FS? In other words, do I need to prevent access to that file for anyone but the AD FS host?

Melvin
  • 111
  • 2

1 Answers1

2

No - it's designed to be publically accessible.

There is no sensitive information. The certificates part is for the public keys only.

rbrayb
  • 1,098
  • 1
  • 12
  • 20