In this article I will try to show how we can use Active Directory Form Based Authentication in Sharepoint 2010 using Lightweight Directory Access Protocol (LDAP)
1. Add Connection string and membership provider in Central Administration web.config
![1.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sd-XJ_BG9ms1dedyp_nEmpQqvfH713kwK97dT5NckimNo_WUiu00hjoPGVWIKE6Nz-5EsIUsEkGBekGDxS6nqC1ggEP9ZshryUIhQkHFeHuGWRDgV16FvfEZyy20GaKEfnyHx7M8oma5sR98PoLS6uX5OaTwSFoZ3-xDFG6B4E-ixT96aj4YrEAgHgPRFtM9cioSLqblVhZl7W79vGtouiXiop=s0-d)
![2.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s4A3t1eB5iTnc2VxiL5wyvZcoEtMBjZ3Vm8nXM12S-OMZwy6fFSJFmriXEBD_yHRdmCVCYDFL1Kam9DayPnWi8Cok2VWUXNHEMBZY4d7-F057aOkZmvzKxB2tLYhRS7Qd-z8l5VFQaVD4fj2fwZtAKM4XhVv6NR8iOvHFrQshCR_YuTImMMOXnS7BA1n8WSCWKi-dXR2yY07BBWtmZ8kaYxk-t=s0-d)
![3.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vfXdjKPf-artOuTADA8exJoypb83Hyqv_Pec5XGttwdstpfst5s75dlCzpiynQLpk6-rhdofLoBPhJcomrScDCivniu8ngn_j_IDz9uFDH7VFKhj4nBPfy8yycuflK7szdA-QV4A5tZLl98tO32BTKShHo9M4d7KLEok7sXLXBsuN0uSknGga4nB-SBF7v99waVTy-Z-FMlqR4BAG-YvM2fgDmJw=s0-d)
![4.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t-1PaD6SeSHdwXHd0jxPhaAvQCW8LkJLipw92EYKCXq0lqIM2FyKAivxK7_DsiS1mz5JrrDnvCX-pJaCsXZ4ckjnczeLs_4lz3x5nkSFyH3hjc3ZQeZlMdOK7S0d3uQmb7iF0ffeJc5-N15G2U9_IYyv57ZbYCg-b-r_NzXhzL9l-j_nYJuYGH6q5W5_fPycMissCK0K_4B6tKHyXU3Yt-yiwE=s0-d)
NOTE: connectionString will differ based on domain configuration. Please contact you Administrator to provide the LDAP details.
NOTE: connectionString will differ based on domain configuration. Please contact you Administrator to provide the LDAP details.
2. Add Connection string and membership provider in SecurityTokenServiceApplication web.config
![5.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uogYE6g_4UxTXxweKuXr6Wz57wQz_lW3zDCVTSrUW553RdHX_sd5ySEoNSaQ0GezLOK4SM3SP1HQfMGLctPzYyyeKghDFjOM87Bl0jGt6bliSbmCFVdG20JCnFlnDYf3b7XsTwDqMBgpRthqEewz7_vHTjwDYy850CandWKuMNyhzZeSwVcPtHPL5fh6O1pH2WSkf4xFOrBDYsCjSSb4umZd0o_g=s0-d)
![6.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s820C1GNMJPTMQFlkjtObCXcBOvfIJJFigaYQvjGvp9ntH8FPCWMnFH73iHrlrZOxaJzyIq7r6T2UroiIcTPNCCgZaU08xZxEALvByF8dIlKBU1fJeoDy5oTJoWbpxql1gyH6OqrTo0laQlychhgBcQUYIyKxNAU9wwfcpWeGzTBoUR2Ltwac46u_1HYAKE5GzWnFiOwoBkZD4DsY5Sak5zE1Cvw=s0-d)
![7.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vdWO7c4CZ0t1ihfpb6Wg32xYuA1H7I0vvJUyfYTen74udnKbWhJZNDAAYCo8STHW2JCtcLwi5J1wElZjgOEhj39rKaOKKnwBczMpQWkpxejAK_27UHciDq2VkR6eXGUZYRDnKdRVp2GhSk0VECfZYj-Njw8T_dIiNd7PA7XUyBg4zBtvcFDQq7ONFKy1w4bBNuMyMcNa8TLnf3CDAu5yr8t4gpVA=s0-d)
NOTE: connectionString will differ based on domain configuration. Please contact you Administrator to provide the LDAP details.
NOTE: connectionString will differ based on domain configuration. Please contact you Administrator to provide the LDAP details.
3. Create a new site with claim based authentication using Central Administration
![8.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tcx0cpnf7GLaEk-YogX_inlCAwZf311ewCNgE0aI6CtXknO959MezAQ3ha6oM-xZh46erv0El61v4ysuLNZscvxdoEtri07SdfA_QKzLC3Nmd0F-kmUICFxmAomZjl3JhS5ocCRh4uorL-z_ytzbtF9wwuvC0tiDLfzRc8Qu1EEkAkGl4OnoWsneZwnYCAQBL4O5_o5qb9Awi7zEoNAusv1RapLA=s0-d)
Authentication : Claim Based
Authentication : Claim Based
Claims Authentication Types: Enable Windows Authentication -> Integrated Windows authentication - > NTLM
Leave others to default
4. Now Create Site Collection at port 2233
![10.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t3goBo7sVHukLkkorThaPDNEwD3V4cdGetXqcbANVolOlnU_t4wjauffmrYW8X6e2FGv9PTnDfjbOsZrxiZUOmVH2Ow8W1aK2GC7hXf0jRqfy4PaLMnouYl5gVjpGus2sVzredzwuPlB8KHt2tX8OyurjCDTlhQq6yIq5QsDYBE2m6azB6AH1iHXTO2zsRYvcx4CLx0ZY_UBUS2Mk6IH5VTe6_iN4=s0-d)
And add Primary / Secondary Site Collection Administrators
![11.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s_70DuoSNx_QlIxgM1jotm_UsUyILIxB2ITKLFN2cMhZ6h6o_OFA-yg7r87oXm6rJKpWxAIh4UzcrbXuHToS5Fn2bioGjbHwB3YNWOUApKVtxL_d-H2CAuVrSF4IRzQWd5Ixoi3jB_wtsL5nQUjGJiN00_ugsHSwT_EuiSYbi8Vslk4qHjFxHdXmfnzS5ELArHIncxpjyYDh3ZbjWs8wqcket_V4o=s0-d)
![12.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v33aqm4mjLCqUd6zK-WQRbZGbQVNzPVnXHcfwJZHEjx8tlmbAp5R0JC7fplbZ2mSikc6MuzRttNfoO5RG4LcvppolV4DvMONnhZp3QqA9erav9x2KCcx0MLgWyvIlbBljyTF9B-LLjAk6j_sCbiPBsQXBUF31F-7hVWmuGROuz-RVMK1Grp0fMV6ukRwr1nVzGeHIY_ERjmLqmC2Bjil6hF92akQ=s0-d)
So the resultant site will look like below.
![13.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tfIoCZ7c-F1_Np1w20nTiERWLhgvVc7s6nzM8hj-h-3KPNN4XfIlJKgn5XisElZS4uVi9B7sNWRdN1yX3J6o_ZrRCh2ATJHvqcFbJn72KcEMjj8gyc9yu760-IOQ-hkKzRPLRrYBv8WiZyb0ZF-8TWtdXjgOMS8IJaEgB2GVg78KDq1xsZJbyq6qRLzG8WDP3g917kZkXFxxk3uHwIfH0AgLeuNA=s0-d)
And add Primary / Secondary Site Collection Administrators
So the resultant site will look like below.
5 Extend the web application to port 3322 and enable form based authentication (FBA)
![14.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tTIhs3nHQLyNHD06bi-k20S7vgFb5n3FPCnrWXtZN6KORFlcGDZboyjzU1JWPfj1nRjX_ffZOF36DnfwPTiBfMRZbVnZy-QWexskngcGzsmsIhFVD81xel-PosmLcwyBdHPyNBGBPljRsYVdqXEa7Lxc26h4QljiEgiFGuPLDH0JxINEgA1AJy7fFAmfoi6hVDTJHiNVHwUkzQXAg7ep-CxtdqB5s=s0-d)
Set the public URL Zone- Intranet or Extranet
Set the public URL Zone- Intranet or Extranet
5. Add Users to the Intranet zone using User Policy
![15.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_syLv9kSr2ABYarIXfjS6E_aEMaBdyyE-gkDRfbT8987KhWTRtWhV6RCnZwGXYJqVH6TQZd7dG5ZP3ST2gnHXU1T8WwT6pmWldxBZzD2v2OJSnucnv8IiutQgiXIjnvUNXtLPKK7EjpK1n5td5-FmcgEl1u85I3e__W__7dgzvM6Z0iE4udooU8Ir4L0f0XVaNr0NWUMLE62tZ_NTLXxojB6Ry0mzM=s0-d)
![16.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uTbA2W6-ckOoUkn5yXVaxheGdttdaL4ANaAR2TQAEYP1NUmXdfpI-DyQjKYj7L1ukicqgMo2UVCbry-fYqO-Uyy1dupVj0Oec-M1uFaCUGHkmFIoH_Lxwfz_18MYRPxTKbQQpQ-3hTAmklLp2p1yWyOqmha9aF7WctmZTQKXpFzLiT7j37EcaMDQxiYvt8YMicwrAs1ewuS5CrHObqeWKlM0vJNsM=s0-d)
![17.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s1OVH0RkN7LUiAYG1uSg2xqeMJQCMAsMvfasciJD8L_BtU2WYkfhGWi0MUC_QVFXg9TP4e7aMfu-w2OkMHJrrFwbMNcXcLQFDkzTMsL3BtnHF1nE8aySjP_lpgLW70nd33pZPN0Y90W7W7-ro2c0UHAW6JaWUI8MSYvOnjwnR7vlVUV5GcST0KljOusB6jovE1ZVTj2VEuuRqDj2kesC_mpcVjB2k=s0-d)
![18.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u0fBlGqytay3pdDNVRTOwMJvw2NCdRpmPFwaLDEaGSNFrPGVEutw0sTHK_GeY-kTejKQJRi1FA1cUrKORZsSI7UBAF-SKBWaqsyprpRahof4Ulrl2DwScR_4aBIb5fauxQL-bplIhHU7KGetUEAbuLQ9WBdN7ecpXwXJtQrgtmA1Uaeg6GyJghg_R7S84NfXHTXNV3jnoeyOWu_W03FTa09jX-vM8=s0-d)
Add more users as required with desired permissions.
Now open the newly extended application, and use your domain credentials to login the app.
Add more users as required with desired permissions.
Now open the newly extended application, and use your domain credentials to login the app.
No comments:
Post a Comment