1,291 questions with Active Directory Federation Services tags
How to create a custom claim on ADFS
Hello, I would like to create a custom rule with ADFS using two attributes in order to combine them like this c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"] =>…
Can we directly call Microsoft server API's by creating custom controls from UI ?
We have an JavaScript, HTML based application integrated with custom policies of Azure Active Directory B2C. Currently we are relying on Microsoft template and modifying the elements from Script side in UI. As per Current implementation we are triggering…
Is there a way to schedule account expiration or automating disabling that syncs to Azure AD?
I use Powershell to set accounts to expire shortly after a users final shift. The problem is that this attribute is not synced to Azure AD and they are still able to log into teams and O365. Our IT staff is only on-premise during regular working hours,…
Future of Federation Service in Windows Server
Is the Federation Service still expected to be available in future versions of Windows Server? What is the information regarding the end of support for the Federation Service on Windows Server?
Promoting a Federated Subdomain to Root: Potential Consequences
Current Setup: We have an Entra ID tenant with an external primary domain (contoso.com) and its subdomain (sub.contoso.com). Both domains are federated using a third-party Identity Provider (Opentext IAM) for Single Sign-On (SSO). As a result, when users…
ADFS web issue
Hi all, i have a strange issue after later windows server update. I usually test adfs service on this page https://<domainurl/adfs/ls and I have a web page where I can inser my credential. Now i receive a generic error Any idea ? Thanks a lot
Configure a domain controller to be isolated
I want to validate what I think I need to do. Here is the situation. Company is selling a location that has an onprem Domain Controller, this domain controller has no schema roles assigned to it. It is the DHCP and DNS server locally as well. The…
The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'urn:oasis:names:tc:SAML:1.0:am:password
We have a Relying Party setup for SSO for a client to our application, however they are unable to log in using SSO. Upon investigation, i have found the below messages within ADFS event logs: The Federation Service could not satisfy a token request…
adfs "token" endpoint for grant_type = refresh_token return only access_token and id_token
Hi , when user authanticate with "Authorization code grant flow" on browser responded refresh_token with access_token. but if i wan't to renew access_token with "Refresh Token Grant Flow" adfs server don't return refresh_token.…
windows 11 pro 24h2 version can not use AD account
1 I joined the AD domain on my windows 11pro version 24h2 computer, but I can't join the administrator user to the local administrators group on the administrator computer. Every time I enter my password it prompts me with the wrong username password,…
Migrate ADFS from Windows 2012 R2 to 2019
I have a Windows 2012 R2 server with ADFS installed on it. However, I am unsure about the farm config as the cmdlet "Get-AdfsFarmInformation" does not work, and instead spits out an error about the cmdlet not being recognised. I am unsure…
how we can add aws ec2 instnace to Azure entra
Customer is having two environment one is on azure and another one aws. on Azure there is entra ID. on AWS customer has created the two ec2 instances. which he wanted to be authenticated using the Azure Entra ID . could you please help us what all things…
Federation Trust Unable to access Federation Metadata
Hello, I have been trying to run the Hybrid Configuration Wizard on our Exchange Server. I know TLS 1.2 is running because I am able to login with my Tenant admin account(at least through IE) in the beginning of the HCW. I have checked all registry keys…
ADFS 3.0 Service won't start because certificate has expired
Hi, I have a fairly urgent issue with ADFS service not starting. The infrastructure is all Server 2019 and the service account password had expired so the ADFS could not auto renew the token signing and decrypting certificate. I know, I should have…
How to verify the AAD Connect is using ADFS for sign-in
Hi Support, We will migrate the ADFS from Win2012R2 to new Win2019 server. The ADFS farm is in another network subnet, so we need to configure the firewall rules for the new ADFS server. Since we have a AAD Connect server, we are not sure any connection…
How to achieve cross app sso with ADFS not entra ID
Based on this article https://learn.microsoft.com/en-us/entra/identity-platform/msal-android-single-sign-on How to achieve Cross APP SSO with ADFS Account? I have my environment running full on premise with ADFS 2019, Exchange server 2019 CU 14. I've…
Create custom CloudAP plugin to authenticate to windows machine which is entra Joined?
My domain is federated with custom inhouse IDP and when the user tries to login in the entra joined machine as IDP CloudAP authenticates the user right? Is it possible to create custom CloudAP Plugin so after user enters the password our idp can enforce…
ADFS external facing site error with 'Service Unavailable HTTP Error 503. The service is unavailable.'
Hi All, We have 2 AD FS (2016) servers, and 2 WAP servers (2016) and recently renewed SSL certificate for ADFS. During the same time, ADFS service account password expired and we updated that as well. SSL renewal steps: Installed the cert with…
The ADFS standard login page shows 503 service unavailable
ADFS running on Windows 2019 in a cluster containing two hosts. After changing the certificate for SSL and Service-Communications using the following commands: Set-AdfsSslCertificate –Thumbprint XXX Set-AdfsCertificate -CertificateType…
OWA/ECP Exchange Server site error after configuring AD FS as an authentication method
Good day! Given: Hyper-V VM running Windows Server 2022 Exchange Server 2019 CU9 is installed on it The SSL certificate is universal: *.chuc228.ru Addresses: https://mail.chuc228.ru/owa/ https://mail.chuc228.ru/ecp/ I have configured AD FS as an…