1,295 questions with Active Directory Federation Services tags
ADFS Windows Server 2022
Hello, there is detailed documentation of adfs 2022. The one I find is only up to 2019. Thank you.
Locked myself out of Entra ID domain, cannot remove Federation (Google as IdP)
Hi! In the process of trying to setup Google as IdP and Azure as SP, I ended up breaking something and now noone from the domain can login ;(. When trying to login to MS services, users enter their username, but and then greeted with "Choose a way…
New-MgDomainFederationConfiguration is failing with 409
It seems that New-MgDomainFederationConfiguration is broken. We need to set federation for a domain which is what this command used to work in past. Now. We registered a new Entra, registered a new domain and set all the verification things. We added the…
AD FS Relying Party Trust Error ID4037
I am building a relying party trust between two separate ADFS servers (I know is not the best, but have some company to company SSO I need) and getting an error when trying to do an idp initiated signon using the Relying Party trust. The error message I…
Assistance Required for Azure Bing Spell Check API Integration
Hi All, We are developing an application that utilizes the Azure Bing Spell Check API for text correction. The Bing API is accessed using an access token, which is generated using a Kubernetes service token. Below are the steps we have…
Microsoft Single Sign On 1.0.8 Google Chrome extension for Linux/Ubuntu ?
Hello, we use SSO in our intranet for various applications. The web browser MS SSO extension is available for Windows and Mac OS. Linux is important platform in our ecosystem but this extension is missing. Could Linux be supported as well? Or is there…
ADFS integration with AWS loadbalancers
Hi, i am trying to integrate ADFS server behind AWS load balancers. Proxy server behind application load balancer and ADFs farm server behind network load balancer however i am getting a 502 bad gateway error. Any suggestions?
ADFS Logout problem MSISignOutProtocol preventing logout attempts
This is a duplicate of ADFS Logout problem on our testing platform - Microsoft Community, however I can't access the link for where the discussion continued. https://[Domain name]/adfs/ls/?wa=wsignout1.0 When user perform login, the below two…
Promoting a Federated Subdomain to Root: Potential Consequences
Current Setup: We have an Entra ID tenant with an external primary domain (contoso.com) and its subdomain (sub.contoso.com). Both domains are federated using a third-party Identity Provider (Opentext IAM) for Single Sign-On (SSO). As a result, when users…

Troubleshooting "Object Reference Not Set to an Instance of an Object" Error in AD FS
I'm encountering an issue while editing claim rules in Active Directory Federation Services (AD FS). When I try to modify claim rules under Claims Provider Trusts, I get the following error message: Unhandled exception has occurred in your application.…
Active Directory Domain User Profile Issue.
Dear Windows Support, Good day! May we seek some advice regarding Active Directory Domain User. please see below inquiries. User A login to a domain member workstation, but user B name appears in the windows upon login. Upon login in the web…
Can we directly call Microsoft server API's by creating custom controls from UI ?
We have an JavaScript, HTML based application integrated with custom policies of Azure Active Directory B2C. Currently we are relying on Microsoft template and modifying the elements from Script side in UI. As per Current implementation we are triggering…
How to create a custom claim on ADFS
Hello, I would like to create a custom rule with ADFS using two attributes in order to combine them like this c:[Type == "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname", Issuer == "AD AUTHORITY"] =>…
Is there a way to schedule account expiration or automating disabling that syncs to Azure AD?
I use Powershell to set accounts to expire shortly after a users final shift. The problem is that this attribute is not synced to Azure AD and they are still able to log into teams and O365. Our IT staff is only on-premise during regular working hours,…

Future of Federation Service in Windows Server
Is the Federation Service still expected to be available in future versions of Windows Server? What is the information regarding the end of support for the Federation Service on Windows Server?
ADFS web issue
Hi all, i have a strange issue after later windows server update. I usually test adfs service on this page https://<domainurl/adfs/ls and I have a web page where I can inser my credential. Now i receive a generic error Any idea ? Thanks a lot
Configure a domain controller to be isolated
I want to validate what I think I need to do. Here is the situation. Company is selling a location that has an onprem Domain Controller, this domain controller has no schema roles assigned to it. It is the DHCP and DNS server locally as well. The…
The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'urn:oasis:names:tc:SAML:1.0:am:password
We have a Relying Party setup for SSO for a client to our application, however they are unable to log in using SSO. Upon investigation, i have found the below messages within ADFS event logs: The Federation Service could not satisfy a token request…
adfs "token" endpoint for grant_type = refresh_token return only access_token and id_token
Hi , when user authanticate with "Authorization code grant flow" on browser responded refresh_token with access_token. but if i wan't to renew access_token with "Refresh Token Grant Flow" adfs server don't return refresh_token.…
windows 11 pro 24h2 version can not use AD account
1 I joined the AD domain on my windows 11pro version 24h2 computer, but I can't join the administrator user to the local administrators group on the administrator computer. Every time I enter my password it prompts me with the wrong username password,…