Microsoft provides best practices for the secure planning and deployment of Active Directory Federation Services (AD FS) and Web Application Proxy.
For hardening your AD FS Microsoft provides a list of best practices and recommendations for hardening and securing your AD FS deployment, which includes also a hardware security module (HSM) attached to AD FS.
You can read more about Microsoft's recommendations here.