Users unable to sign into Azure AD joined W10 Devices

Jacob Cunningham 21 Reputation points
2022-12-09T10:51:33+00:00

Hi,

Bit of a weird issue we are having.

We are starting to roll out Azure AD joined Windows 10 devices to our users. An issue that we noticed yesterday is that any new users that want to sign into these devices is unable to login - error just says something like: "Your network is unavailable, please check your connection and try again later"

The network is fine on them, if a user who has already logged in they can get in fine and use it as normal, it's just if any new user wants to log in they get this error. They are getting an IP address but not getting a reply when pinging them. This is the same on any network, not just in the office. Have taken a laptop home and used my mobile hotspot. What is also throwing a bit of a spanner in the works is that we also use ADFS - This stopped working a few days back, but was subsequently fixed (issue with service account not having correct permissions to run as service) and now it seems to be all OK, but I do wonder if this is what could be causing issues... logs on ADFS look fine.

We are able to enroll new machines into Intune fine.

Any ideas on what could be causing this??

Thanks for reading.

Jacob

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,301 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,637 questions
{count} votes

Accepted answer
  1. Akshay-MSFT 17,941 Reputation points Microsoft Employee Moderator
    2022-12-21T04:14:28.347+00:00

    Hello @Jacob Cunningham ,

    From the description you just shared this is similar to issues documented https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/sign-in/federated-users-sign-in-error-ad-fs.

    This issue may occur for one of the following reasons:

    1. The setup of single sign-on (SSO) through AD FS wasn't completed.
    2. The AD FS token-signing certificate expired.
    3. The AD FS client access policy claims are set up incorrectly.
    4. The relying party trust with Azure Active Directory (Azure AD) is missing or is set up incorrectly.
    5. The AD FS federation proxy server is set up incorrectly or exposed incorrectly.
    6. The AD FS IUSR account doesn't have the "Impersonate a client after authentication" user permission.
    7. Hash Algorithm to be updated to SHA-256

    Kindly validate the solution given and if the issue persist please do let me know in the comments section.

    Thanks,
    Akshay Kaushik

    Please "Accept the answer", "Upvote" and rate your experience if the suggestion works as per your business need. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.