OK, so ISA provides single sign on, but doesn't do federation. ADFS does sso and federation. IAG can potentially mix ISA and ADFS, is there a reason you would want to?
If ISA is doing some sso currently in one "realm" do we just scrap the authentication of ISA and replace it with ADFS, or do we keep ISA as a middle man and get ADFS to authenticate to ISA which then authenticates to the resources?
No one seems to know anything, and on the news groups all I heard was, "use IAG"
any ideas?