Is there a way to manually and safely serialize Session Security Token?
I am setting up a web application that authenticates with Azure ACS.
I have got the claims and principals ok. Now I need to pass that whole thing to back end services. What's the best way to do this?
There is not best way. The most standard way is to use a wsFederationHttpBinding on your wcf back-end services. This way your security token can arrive at the back end and the back end cannot be called (unless you expose other bindings) without a valid token.