Mostly a reminder for myself, but hopefully useful to somebody else - Often it is important to specify a specific user for a service to run as; it appears the setup is completely different when using IIS 5.1 or 6 (and higher). When using IIS 5.1 Set the anonymous user on the virtual directory to the user you want to run as. Disable any other authentication method on the vdir In the web.config turn impersonation ON (<identity impersonate="true" /> under System.web.) Under System.serviceModel ......

In my previous blog post I’ve described how I consumed a service that uses ws2007FederationHttpBinding from BizTalk Server; my next task was to expose an orchestration as a WCF service that uses this binding. In that post I’ve described what I think is a bug in BizTalk R2/2009 which prevents me from setting the issuer configuration through the UI. When consuming such a service this configuration exists in the send port, and I’ve managed to get enough time to manually edit a BizTalk bindings file ......

Finally I’ve reached the point where I’m ready to hook up BizTalk to my STS implementation to participate in a federated identity scenario. My goal is to confirm two scenarios - 1. Being able to call from a BizTalk process a service that uses the ws2007FederationHttpBinding (and requires that the caller provide a token issued by a specific STS) 2. Being able to expose a service in BizTalk that would use the ws2007FederationHttpBinding requiring the caller to provide such token. If you followed my ......

