1,284 questions with Active Directory Federation Services tags
windows 11 pro 24h2 version can not use AD account
1 I joined the AD domain on my windows 11pro version 24h2 computer, but I can't join the administrator user to the local administrators group on the administrator computer. Every time I enter my password it prompts me with the wrong username password,…
Migrate ADFS from Windows 2012 R2 to 2019
I have a Windows 2012 R2 server with ADFS installed on it. However, I am unsure about the farm config as the cmdlet "Get-AdfsFarmInformation" does not work, and instead spits out an error about the cmdlet not being recognised. I am unsure…
how we can add aws ec2 instnace to Azure entra
Customer is having two environment one is on azure and another one aws. on Azure there is entra ID. on AWS customer has created the two ec2 instances. which he wanted to be authenticated using the Azure Entra ID . could you please help us what all things…
Federation Trust Unable to access Federation Metadata
Hello, I have been trying to run the Hybrid Configuration Wizard on our Exchange Server. I know TLS 1.2 is running because I am able to login with my Tenant admin account(at least through IE) in the beginning of the HCW. I have checked all registry keys…
ADFS 3.0 Service won't start because certificate has expired
Hi, I have a fairly urgent issue with ADFS service not starting. The infrastructure is all Server 2019 and the service account password had expired so the ADFS could not auto renew the token signing and decrypting certificate. I know, I should have…
How to verify the AAD Connect is using ADFS for sign-in
Hi Support, We will migrate the ADFS from Win2012R2 to new Win2019 server. The ADFS farm is in another network subnet, so we need to configure the firewall rules for the new ADFS server. Since we have a AAD Connect server, we are not sure any connection…
How to achieve cross app sso with ADFS not entra ID
Based on this article https://learn.microsoft.com/en-us/entra/identity-platform/msal-android-single-sign-on How to achieve Cross APP SSO with ADFS Account? I have my environment running full on premise with ADFS 2019, Exchange server 2019 CU 14. I've…
Create custom CloudAP plugin to authenticate to windows machine which is entra Joined?
My domain is federated with custom inhouse IDP and when the user tries to login in the entra joined machine as IDP CloudAP authenticates the user right? Is it possible to create custom CloudAP Plugin so after user enters the password our idp can enforce…
ADFS external facing site error with 'Service Unavailable HTTP Error 503. The service is unavailable.'
Hi All, We have 2 AD FS (2016) servers, and 2 WAP servers (2016) and recently renewed SSL certificate for ADFS. During the same time, ADFS service account password expired and we updated that as well. SSL renewal steps: Installed the cert with…
The ADFS standard login page shows 503 service unavailable
ADFS running on Windows 2019 in a cluster containing two hosts. After changing the certificate for SSL and Service-Communications using the following commands: Set-AdfsSslCertificate –Thumbprint XXX Set-AdfsCertificate -CertificateType…
OWA/ECP Exchange Server site error after configuring AD FS as an authentication method
Good day! Given: Hyper-V VM running Windows Server 2022 Exchange Server 2019 CU9 is installed on it The SSL certificate is universal: *.chuc228.ru Addresses: https://mail.chuc228.ru/owa/ https://mail.chuc228.ru/ecp/ I have configured AD FS as an…
New-MgDomainFederationConfiguration is failing with 409
It seems that New-MgDomainFederationConfiguration is broken. We need to set federation for a domain which is what this command used to work in past. Now. We registered a new Entra, registered a new domain and set all the verification things. We added the…
How to fix ADFS missing endpoints
The endpoints /token and /authorize for OAuth2 are not available in AD FS Management -> Services -> Endpoints, making it impossible to use OAuth2 with third-party applications. The only endpoints related to OAuth2 are: OAuth2: …
ADFS 2016 login using Azure MFA encountered error
I've set up Azure MFA with ADFS following https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa. To test, I browsed to https://[myadfs].com/adfs/ls/idpinitiatedsignon Clicked "Azure…
"Certificate Templates" container missing in Certification Authority (Local) MMC snap-in
I'm trying to follow the directions here to set up an SSL Certificate for AD FS: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn781428(v=ws.11) In the "Assign a template to a CA" section…
After updating SharePoint On-Premisue with ADFS some users can't work because of old Auth-Cookie (MSIS7042)
We already made a few updates from SharePoint 2013 to 2016 or 2019 successfully. When using ADFS-Authentication and preserving the same SiteCollection-URL on the new SharePoint Server, some users may still have an Authentication-Cookie for the URL but…
the service account created for O365 ADFS is interactive or non-interactive? Need domain admin priv?
I am working on identifying service accounts that allows interactive logins. Is there a way to check that? One of the accounts is used for Active Directory Federation Service (AD FS). Wanted to check if this allows interactive logins or not? Since it…
How to fix the SAML Error Request not signed. Policy requires signed authentication requests
I followed the steps in the this guide: https://learn.microsoft.com/en-us/azure/active-directory-b2c/saml-service-provider?tabs=windows&pivots=b2c-custom-policy. However, on the last step, when trying to test my SAML setup with the provided Test App,…
ADFS Cookie Handling Issue with SamlSession
I'm experiencing issues with ADFS cookie handling. After creating a Relying Party Trust, everything seemed to work fine initially. However, when calling ADFS repeatedly with the same user, the SamlSession cookie size gradually increases, leading to a 400…
Turning off Seamless single sign-on - AZUREADSSOACC - Seamless SSO object for Microsoft Entra Connect
I need some help and guidance in Turning off Seamless single sign-on as we are already using Hybrid Azure AD / Entra ID with Password Hash Sync. There is an AD object called AZUREADSSOACC - Seamless SSO object for Microsoft Entra Connect. What will be…