AD FS (3.0) for Windows Server 2012 R2 Troubleshooting: Configuration with GMSA fails with 'The system cannot find the file specified' and other errors
Issue
When choosing to add a federation server to an existing farm that uses a Group-Managed Service Account (GMSA), or creating the first server in a federation farm after pre-staging a GMSA, the AD FS Configuration Wizard pre-requisite check fails with a string of errors beginning with The system cannot find the file specified.
** Note:** This will occur when using WID or SQL for the AD FS backend databases
Event log errors
None! |
There are no errors in the event log, but the error in the configuration wizard hints at the problem. If you look closely at each error thrown, you will notice several are relating to the GMSA, specifically the inability to resolve the account. You may notice this error even if Test-ADServiceAccount returns true.
Cause
The GMSA was moved from the Managed Service Accounts container in Active Directory.
Resolution
Move the GMSA back to the Managed Service Accounts container in Active Directory**.**