adfs and exchange 2016

Myshkin 46 Reputation points
2020-11-17T20:22:53.213+00:00

Two wap and two adfs 3.0 in use with exchange 2013 for owa and ecp. It has been working fine.

Exchange 2016 was added to the organization for migration. However, pointing the dns identifier to 2016 sso doesn't work. Only regular prompt is received.

Since 2016 uses the same organization settings as 2013 not sure what is missing. Token signing cert thumbprint matches. Had adfs authentication set to true (with others false) on virtual directory as mentioned in the article below and that didn't work.
https://learn.microsoft.com/en-us/exchange/clients/outlook-on-the-web/ad-fs-claims-based-auth?view=exchserver-2019
Also, imported the cert to 2016 box root store. didn't work.

Thanks.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,261 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,636 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 148.1K Reputation points MVP
    2020-11-17T20:54:15.157+00:00

    What do you mean by "dns identifier" points to 2016 SSO?

    What is the AdfsAudienceUris set to?

    Get-OrganizationConfig |FL *ADFS*  
    

    The 2016 virtual dirs need to be defined there
    https://learn.microsoft.com/en-us/powershell/module/exchange/set-organizationconfig?view=exchange-ps
    https://learn.microsoft.com/en-us/exchange/clients/outlook-on-the-web/ad-fs-claims-based-auth?view=exchserver-2019#step-6-configure-the-exchange-organization-to-use-ad-fs-authentication

    Set-OrganizationConfig -AdfsIssuer https://<FederationServiceName>/adfs/ls/ -AdfsAudienceUris "<OotwURL>","<EACURL>" -AdfsSignCertificateThumbprint "   
    

    <Thumbprint>"

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Eric Yin-MSFT 4,386 Reputation points
    2020-11-18T07:48:10.35+00:00

    Hi,
    Can you post the result of " Get-OrganizationConfig |FL ADFS "?
    I just wonder if you add "/" at the end of each url:

    The inclusion of the trailing slash / in the URL examples shown below is intentional. It’s important to ensure that both the AD FS relying party trusts and Exchange Audience URI’s are identical. This means the AD FS relying party trusts and Exchange Audience URI’s should both have or both emit the trailing slashes in their URLs. The examples in this section contain the trailing /’s after any url ending with “owa” ( /owa/) or “ecp” (/ecp/).


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.