ptilsen wrote: » Hold on a second. You don't need ADFS to implement single-sign on within one forest or domain. While you could use it for that purpose, it would be an excessive solution. ADFS is primarily intended to create trust relationships between different organizations (read: different forests, different network) for web applications. This Technet article should give you a good overview:Active Directory Federation Services Overview
method115 wrote: » So what would you suggest instead of ADFS? We use a lot of web based applications and having something like ADFS would just make it all easier to maintain when it comes to our users.