Active Directory Federation Services (AD FS) is a component of Active Directory (AD), an identity directory service for users, computers, and applications that is developed and marketed by Microsoft for use on Windows domains. AD FS
provides AD users with the ability to access off-domain resources (i.e. web-based services or another domain) using their AD domain credentials. AD FS uses the concept of identity federation to allow users on one domain to access another domain without needing to authenticate separately to the other domain.
To enable identity federation, a trust relationship is established between two domains – the one where AD FS is running and an external resource/domain. Once trust is established, AD FS can provide attestations about the authenticated identities of users to the external domain instead of requiring users to authenticate separately.