1,288 questions with Active Directory Federation Services tags
How can I migrate from federation to cloud authentication?
My environment is: 1 domain (e.g. XXXX.com) on 1 on-prem AD (with 2 OU) 2 Entra ID tenants with each domain (e.g. YYYY.com and ZZZZ.com) 1 ADFS 1 Entra ID Connect Now, I login Microsoft 365 via Entra ID and ADFS. One OU members belong to YYYY.com…
Future of Federation Service in Windows Server
Is the Federation Service still expected to be available in future versions of Windows Server? What is the information regarding the end of support for the Federation Service on Windows Server?
Configure a domain controller to be isolated
I want to validate what I think I need to do. Here is the situation. Company is selling a location that has an onprem Domain Controller, this domain controller has no schema roles assigned to it. It is the DHCP and DNS server locally as well. The…
The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'urn:oasis:names:tc:SAML:1.0:am:password
We have a Relying Party setup for SSO for a client to our application, however they are unable to log in using SSO. Upon investigation, i have found the below messages within ADFS event logs: The Federation Service could not satisfy a token request…
adfs "token" endpoint for grant_type = refresh_token return only access_token and id_token
Hi , when user authanticate with "Authorization code grant flow" on browser responded refresh_token with access_token. but if i wan't to renew access_token with "Refresh Token Grant Flow" adfs server don't return refresh_token.…
windows 11 pro 24h2 version can not use AD account
1 I joined the AD domain on my windows 11pro version 24h2 computer, but I can't join the administrator user to the local administrators group on the administrator computer. Every time I enter my password it prompts me with the wrong username password,…
Migrate ADFS from Windows 2012 R2 to 2019
I have a Windows 2012 R2 server with ADFS installed on it. However, I am unsure about the farm config as the cmdlet "Get-AdfsFarmInformation" does not work, and instead spits out an error about the cmdlet not being recognised. I am unsure…
how we can add aws ec2 instnace to Azure entra
Customer is having two environment one is on azure and another one aws. on Azure there is entra ID. on AWS customer has created the two ec2 instances. which he wanted to be authenticated using the Azure Entra ID . could you please help us what all things…
Federation Trust Unable to access Federation Metadata
Hello, I have been trying to run the Hybrid Configuration Wizard on our Exchange Server. I know TLS 1.2 is running because I am able to login with my Tenant admin account(at least through IE) in the beginning of the HCW. I have checked all registry keys…
ADFS 3.0 Service won't start because certificate has expired
Hi, I have a fairly urgent issue with ADFS service not starting. The infrastructure is all Server 2019 and the service account password had expired so the ADFS could not auto renew the token signing and decrypting certificate. I know, I should have…
How to verify the AAD Connect is using ADFS for sign-in
Hi Support, We will migrate the ADFS from Win2012R2 to new Win2019 server. The ADFS farm is in another network subnet, so we need to configure the firewall rules for the new ADFS server. Since we have a AAD Connect server, we are not sure any connection…
How to achieve cross app sso with ADFS not entra ID
Based on this article https://learn.microsoft.com/en-us/entra/identity-platform/msal-android-single-sign-on How to achieve Cross APP SSO with ADFS Account? I have my environment running full on premise with ADFS 2019, Exchange server 2019 CU 14. I've…
Create custom CloudAP plugin to authenticate to windows machine which is entra Joined?
My domain is federated with custom inhouse IDP and when the user tries to login in the entra joined machine as IDP CloudAP authenticates the user right? Is it possible to create custom CloudAP Plugin so after user enters the password our idp can enforce…
ADFS external facing site error with 'Service Unavailable HTTP Error 503. The service is unavailable.'
Hi All, We have 2 AD FS (2016) servers, and 2 WAP servers (2016) and recently renewed SSL certificate for ADFS. During the same time, ADFS service account password expired and we updated that as well. SSL renewal steps: Installed the cert with…
The ADFS standard login page shows 503 service unavailable
ADFS running on Windows 2019 in a cluster containing two hosts. After changing the certificate for SSL and Service-Communications using the following commands: Set-AdfsSslCertificate –Thumbprint XXX Set-AdfsCertificate -CertificateType…
OWA/ECP Exchange Server site error after configuring AD FS as an authentication method
Good day! Given: Hyper-V VM running Windows Server 2022 Exchange Server 2019 CU9 is installed on it The SSL certificate is universal: *.chuc228.ru Addresses: https://mail.chuc228.ru/owa/ https://mail.chuc228.ru/ecp/ I have configured AD FS as an…
New-MgDomainFederationConfiguration is failing with 409
It seems that New-MgDomainFederationConfiguration is broken. We need to set federation for a domain which is what this command used to work in past. Now. We registered a new Entra, registered a new domain and set all the verification things. We added the…
How to fix ADFS missing endpoints
The endpoints /token and /authorize for OAuth2 are not available in AD FS Management -> Services -> Endpoints, making it impossible to use OAuth2 with third-party applications. The only endpoints related to OAuth2 are: OAuth2: …
ADFS 2016 login using Azure MFA encountered error
I've set up Azure MFA with ADFS following https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa. To test, I browsed to https://[myadfs].com/adfs/ls/idpinitiatedsignon Clicked "Azure…
"Certificate Templates" container missing in Certification Authority (Local) MMC snap-in
I'm trying to follow the directions here to set up an SSL Certificate for AD FS: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn781428(v=ws.11) In the "Assign a template to a CA" section…