{"id":863,"date":"2014-03-08T22:38:19","date_gmt":"2014-03-08T22:38:19","guid":{"rendered":"http:\/\/blog.lync2013.org\/?p=863"},"modified":"2014-05-07T13:21:51","modified_gmt":"2014-05-07T13:21:51","slug":"configure-windows-2012-r2-workplace-join-enable-ipad","status":"publish","type":"post","link":"https:\/\/modern-workplace.uk\/?p=863","title":{"rendered":"Configure Windows 2012 R2 Workplace Join and Enable an IPad"},"content":{"rendered":"<p>Active Directory Federation Services (AD FS) in Windows 2012 R2 have reached the release 3.0.\u00a0In the long list of new features, an interesting one (dedicated to the world of BYOD) is the workplace join. I have configured workplace join in my lab and used it to authenticate an IPad. The following post explains and shows all the required steps.<\/p>\n<p><strong>Note<\/strong>: the full configuration video is available here <a href=\"http:\/\/www.youtube.com\/watch?v=vQk2sF-tqf8&amp;list=UUREnpjKgVEWhBxLU9yEDmXQ%20\">http:\/\/www.youtube.com\/watch?v=vQk2sF-tqf8&amp;list=UUREnpjKgVEWhBxLU9yEDmXQ\u00a0<\/a><\/p>\n<address>\n<hr \/>\n<\/address>\n<h4>Before We Start: Introduction to Workplace Join<\/h4>\n<p>Workplace join answer to the need, for users to access company resources from their devices without giving the control on them to the network administrators. However it answers also to the need of the IT staff to keep control on what the device is able to do on the corporate resources. Workplace join enables users to register Windows-based and IOS-based devices for single sign-on and access to corporate data. The aforementioned device ado not join Active Directory, but the workplace join process generates a device object in AD and installs a certificate inside the device. From now on the network administrators are able to use this authentication to allow or remove access to network resources for the device, while users enjoy a single sign-on experience.<\/p>\n<p>To realize my lab, I have used as a starting base this good post from Keith Mayer \u201c<i>Why R2? Step-by-Step: Solve BYOD Challenges with Workplace Join in Windows Server 2012 R2 and Windows 8.1<\/i>\u201d <a href=\"http:\/\/bit.ly\/1fc034K\">http:\/\/bit.ly\/1fc034K<\/a><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<h4><span style=\"font-family: Georgia, Palatino;\">Step by step procedure<\/span><\/h4>\n<p><span style=\"font-family: Georgia, Palatino;\">First step has been to add the Active Directory Federation Services role to my server Aphrodite (that is also my Domain Controller and Certification Authority).<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/DhJ3g1oKzy0\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">The configuration of the AD FS role requires a service account, so I created a Group Managed Service Account called FsGmsa with the following cmdlets (adapting the ones used by Keith)<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">Add-KdsRootKey \u2013EffectiveTime (Get-Date).AddHours(-10)<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">New-ADServiceAccount FsGmsa -DNSHostName Aphrodite.lync2013.corp -ServicePrincipalNames http\/Aphrodite.lync2013.corp<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/aVSyJiC4F8o\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">An SSL certificate is required too, so I used my beloved DigiCertUtil to create a CSR. Please note that the Common Name must be the FQDN of the AD FS server, and you need the same name as Subject Alternative Name too. In the SAN names, enterpriseregistration.yourdomain is REQUIRED too.<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/AK_byMbDwPQ\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">I have used a command line to submit the request and generate the SSL certificate<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">certreq -submit -attrib &#8220;CertificateTemplate:WebServer&#8221; C:UsersAdministrator.WIN-VSNVH4NJGUFDesktopAphrodite_lync2013_corp.txt<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/w7Y1S9l-ZYc\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">Then I have imported (and verified) the aforementioned certificate.<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/A8q3upFB2NM\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">With all the requirements satisfied, I have launched the configuration of the AD FS role<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/qFJD48RF2L0\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">I have defined a standard user, Ipaduser, (I will use it to simulate a real world scenario of a domain user joining his\/her IPad to the domain).<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/parfnTDrXYE\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">I have exported my root CA certificate in a .cer file and copied it on Google Drive (because I need to open it from Safari on the IPad later)<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">Next step is to initialize the Device Registration Service that, by default, is disabled and stopped. I used the Initialize-ADDeviceRegistrationcmdlet, using, as ServiceAccount, the previously configured Lync2013fsgmsa$<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/VsRX1GZZ8f4\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><br \/>\n<span style=\"font-family: Georgia, Palatino;\"> Open the .cer file of the root CA inside Safari and import it as a profile<\/span><\/p>\n<figure id=\"attachment_1086\" aria-describedby=\"caption-attachment-1086\" style=\"width: 400px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0014.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1086\" src=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0014.png\" alt=\"IMG_0014\" width=\"400\" height=\"533\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0014.png 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0014-225x300.png 225w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0014-200x266.png 200w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0014-337x450.png 337w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption id=\"caption-attachment-1086\" class=\"wp-caption-text\">Importing Root CA in the IPad<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">Open the following url <a href=\"https:\/\/aphrodite.lync2013.corp\/enrollmentserver\/otaprofile\" target=\"_blank\">https:\/\/aphrodite.lync2013.<wbr \/>corp\/enrollmentserver\/<wbr \/>otaprofile<\/a> and Authenticate with Lync2013IPaduser<\/span><\/p>\n<figure id=\"attachment_1085\" aria-describedby=\"caption-attachment-1085\" style=\"width: 400px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0007.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1085\" src=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0007.png\" alt=\"Authentication from Safar\" width=\"400\" height=\"533\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0007.png 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0007-225x300.png 225w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0007-200x266.png 200w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0007-337x450.png 337w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption id=\"caption-attachment-1085\" class=\"wp-caption-text\">Authentication from Safar<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">Accept the Workplace Join profile<\/span><\/p>\n<figure id=\"attachment_1087\" aria-describedby=\"caption-attachment-1087\" style=\"width: 400px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0022.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1087\" src=\"https:\/\/modern-workplace.uk\/\/wp-content\/uploads\/2014\/05\/IMG_0022.png\" alt=\"\" width=\"400\" height=\"533\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0022.png 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0022-225x300.png 225w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0022-200x266.png 200w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2014\/05\/IMG_0022-337x450.png 337w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption id=\"caption-attachment-1087\" class=\"wp-caption-text\">Accepted Workplace Join<\/figcaption><\/figure>\n<p><span style=\"font-family: Georgia, Palatino;\">Then, back to the Aphrodite D.C. I have verified that the device was registered inside A.D.<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\"><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/7WzQS3ECVTY\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">\u00a0<\/span><\/p>\n<p><span style=\"font-family: Georgia, Palatino;\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Configure Windows 2012 R2 Workplace Join and Enable an IPad <\/p>\n","protected":false},"author":1,"featured_media":1222,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[18,14],"tags":[351,352,353,354,355,356,357,358,359,455,178,360,361,362,363],"class_list":["post-863","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-english","category-microsoft","tag-2012-r2-ad-fs","tag-2012-r2-federation-services","tag-ad-fs","tag-byod","tag-ipad","tag-join-ipad-active-directory","tag-microsoft-byod","tag-use-ipad-domain","tag-use-ipad-windows","tag-windows-2012-features","tag-windows-2012-r2","tag-windows-2012-r2-federation-services","tag-windows-8-1","tag-windows-server-2012-r2","tag-workplace-join"],"_links":{"self":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=863"}],"version-history":[{"count":4,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/863\/revisions"}],"predecessor-version":[{"id":1190,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/863\/revisions\/1190"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/media\/1222"}],"wp:attachment":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}