We were hoping to use ADFS with our WIF-based web application but there appears to be a serious deficiency.
Our configuration is the highly recommended:
IdP's <-> FP (ADFS) <-> RP
where the RP is our application (WIF/WS-Federation) and we have many IdP's (our customers) using various SAML products.
ADFS works marvelously in the RP-initiated Web SSO protocol.
However, if I understand the dozen or so postings in this forum, ADFS does not work at all in this configuration with the IdP-initiated protocol.
So, ADFS is a total non-starter for us unless we are able to insist ALL of our customers use RP-initiated.
Is this correct?
Bill