AD FS Tracing/Debug Event 153 - None of the UPNs were successful for S4U Logon call

Vaman D 5 Reputation points
2023-01-11T14:34:32.6466667+00:00

While trying to login on ADFS page login page, page get refresh and ask for login again (ADFS login loop). When I checked event log in AD FS Tracing/Debug I am getting event 153 with message "None of the UPNs were successful for S4U Logon call" for 2 of secondary ADFS server in our ADFS farm. Please help.

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,532 questions
Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,194 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. James, Jonathan 0 Reputation points
    2024-03-12T09:35:45.7633333+00:00

    Check the AD account that is running the ADFS service. We noticed that ours was in the "protected Users" group. As soon as we removed it from this group, and restarted the ADFS service we were able to logon.

    0 comments No comments