Interfacing ADFS with Peoplesoft and other web-applications.
My organization right now is using PeopleSoft, Hyperion and ECM applications. We have SSO (OAM 11.1.1.5 BP06 and OVD 11.1.1.5) enabled for all applications; however, my manager is asking if we can use ADFS for all of them. His idea is to find a way so that once a user authenticates with ADFS account he does not require any more authentication. I have Kerberos/NWA as a solution to suggest but it seems my manager is more interested in interfacing ADFS to authenticate users to our applications that are web-based. The option of using SAML 2.0 is also available.
Considering security and complexity, which solution best solves this issue?