1,282 questions with Active Directory Federation Services tags
New-MgDomainFederationConfiguration is failing with 409
It seems that New-MgDomainFederationConfiguration is broken. We need to set federation for a domain which is what this command used to work in past. Now. We registered a new Entra, registered a new domain and set all the verification things. We added the…
how we can add aws ec2 instnace to Azure entra
Customer is having two environment one is on azure and another one aws. on Azure there is entra ID. on AWS customer has created the two ec2 instances. which he wanted to be authenticated using the Azure Entra ID . could you please help us what all things…
OWA/ECP Exchange Server site error after configuring AD FS as an authentication method
Good day! Given: Hyper-V VM running Windows Server 2022 Exchange Server 2019 CU9 is installed on it The SSL certificate is universal: *.chuc228.ru Addresses: https://mail.chuc228.ru/owa/ https://mail.chuc228.ru/ecp/ I have configured AD FS as an…
How to achieve cross app sso with ADFS not entra ID
Based on this article https://learn.microsoft.com/en-us/entra/identity-platform/msal-android-single-sign-on How to achieve Cross APP SSO with ADFS Account? I have my environment running full on premise with ADFS 2019, Exchange server 2019 CU 14. I've…
Federation Trust Unable to access Federation Metadata
Hello, I have been trying to run the Hybrid Configuration Wizard on our Exchange Server. I know TLS 1.2 is running because I am able to login with my Tenant admin account(at least through IE) in the beginning of the HCW. I have checked all registry keys…
How to fix ADFS missing endpoints
The endpoints /token and /authorize for OAuth2 are not available in AD FS Management -> Services -> Endpoints, making it impossible to use OAuth2 with third-party applications. The only endpoints related to OAuth2 are: OAuth2: …
ADFS 2016 login using Azure MFA encountered error
I've set up Azure MFA with ADFS following https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa. To test, I browsed to https://[myadfs].com/adfs/ls/idpinitiatedsignon Clicked "Azure…
"Certificate Templates" container missing in Certification Authority (Local) MMC snap-in
I'm trying to follow the directions here to set up an SSL Certificate for AD FS: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn781428(v=ws.11) In the "Assign a template to a CA" section…
windows 11 pro 24h2 version can not use AD account
1 I joined the AD domain on my windows 11pro version 24h2 computer, but I can't join the administrator user to the local administrators group on the administrator computer. Every time I enter my password it prompts me with the wrong username password,…
After updating SharePoint On-Premisue with ADFS some users can't work because of old Auth-Cookie (MSIS7042)
We already made a few updates from SharePoint 2013 to 2016 or 2019 successfully. When using ADFS-Authentication and preserving the same SiteCollection-URL on the new SharePoint Server, some users may still have an Authentication-Cookie for the URL but…
the service account created for O365 ADFS is interactive or non-interactive? Need domain admin priv?
I am working on identifying service accounts that allows interactive logins. Is there a way to check that? One of the accounts is used for Active Directory Federation Service (AD FS). Wanted to check if this allows interactive logins or not? Since it…
How to fix the SAML Error Request not signed. Policy requires signed authentication requests
I followed the steps in the this guide: https://learn.microsoft.com/en-us/azure/active-directory-b2c/saml-service-provider?tabs=windows&pivots=b2c-custom-policy. However, on the last step, when trying to test my SAML setup with the provided Test App,…
ADFS Cookie Handling Issue with SamlSession
I'm experiencing issues with ADFS cookie handling. After creating a Relying Party Trust, everything seemed to work fine initially. However, when calling ADFS repeatedly with the same user, the SamlSession cookie size gradually increases, leading to a 400…
Turning off Seamless single sign-on - AZUREADSSOACC - Seamless SSO object for Microsoft Entra Connect
I need some help and guidance in Turning off Seamless single sign-on as we are already using Hybrid Azure AD / Entra ID with Password Hash Sync. There is an AD object called AZUREADSSOACC - Seamless SSO object for Microsoft Entra Connect. What will be…
ADFS MSIS7065: There are no Registered protocol handlers on path /adfs/ls/idpinitialtedSignon.aspx
Can anyone suggest what causing this issue and a fix? The OS is Windows server 2022, hosted on VM workstation 16.5 configuring the ADFS service, I get the following message when accessing https://adfs.ldlt.com/adfs/ls/idpinitiatedSignon.aspx on the…
windows hello for business On-Premises deployment error event
I try to deploy the on-prem HfB. We are running at domain function level of 2012R2. The single AD FS server runs 2019. I followed exactly the microsoft guide. But when I start my domain PC, the enroll process never happen. Here is the event 1021 messge…
An error occured executing Update ADFS Federated AAD Trust task in Entra Connect
Hello MS Q&A Community, I encountered a strange problem when trying to federate one of our domains with Entra ID in Entra Connect. Our ADFS service is located on a separate Windows 2016 server, has a public name like adfs.domain.com and internal…
I am getting replication issue for my new promoted DC
SYSVOL and NETLOGON Shares Missing on New DC I want to migrate from window server 2012 R2 to Window Server 2022 but when promote it's not syncing the policies and netlogon which is missing. I tried creating the both files and tried authoritative and…
When performing SAML authentication using AD FS, you are not redirected to the authentication screen
現在サードパーティ製品から、AD FSをIdpとしてSAML認証を行うための設定を行っています。 その際に状況に応じて、認証画面へリダイレクトされる、されないが変わります。 ・リダイレクト可能 AD FSがイントラネット(AD FSのあるLAN環境)にある環境下のクライアント端末から、SPへ接続する際は認証画面まで正常にリダイレクトされます。 ・リダイレクト不可 AD…
Ensure privileged accounts are not delegated - Recommendation
Hi, There is a recommendation MS Defender portal about 'Ensure privileged accounts are not delegated'. The list contains all our Domain Controllers, ADFS, Print Servers and 1 MSOL_Account. My questions is, is it safe to enable these? Or I should not…