Share via


AD FS (3.0) for Windows Server 2012 R2 Troubleshooting: Configuration with GMSA fails with 'The system cannot find the file specified' and other errors

Issue

When choosing to add a federation server to an existing farm that uses a Group-Managed Service Account (GMSA), or creating the first server in a federation farm after pre-staging a GMSA, the AD FS Configuration Wizard pre-requisite check fails with a string of errors beginning with The system cannot find the file specified.

** Note:** This will occur when using WID or SQL for the AD FS backend databases

Event log errors

None!

There are no errors in the event log, but the error in the configuration wizard hints at the problem.  If you look closely at each error thrown, you will notice several are relating to the GMSA, specifically the inability to resolve the account.  You may notice this error even if Test-ADServiceAccount returns true.

Cause

The GMSA was moved from the Managed Service Accounts container in Active Directory.    

Resolution

Move the GMSA back to the Managed Service Accounts container in Active Directory**.**