How to migrate a Relying Party Trust in ADFS for Office 365 (EntryID) to a new Forest

Michael Zahneißen 0 Reputation points
2024-03-14T15:29:21.0033333+00:00

We need to migrate ADFS (>5 years old) from an old AD forest to the new Forest. We use ADFS, among other things, for SSO with custom domains for EntraID.

For federation and creating the relying party with EntraID (Office 365 / Microsoft 365) I used to work with Powershell and MSOLService, which is outdated. Microsoft's recommendation is to use MSGraph with something in Powershell like New-MgDomainFederationConfiguration or Update-MgDomainFederationConfiguration. Unfortunately, no configuration of the ADFS is carried out here. Also I couldn't find any documentation for federation with ADFS and MS Graph.

In my tests to federate a new domain, I was able to federate it in EntraID, but I cannot delete or change it. The -InternalDomainFederationId is required for this, but it is not displayed anywhere.

What am I doing wrong and how do I do it right? Is there corresponding documentation.

Configuring ADFS via AzureADConnect is out of the question in this case.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,821 questions
Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,468 questions
Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
10,630 questions
Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,192 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,544 questions
{count} votes