ADFS Service Account required to be in Enterprise Key Admin

Lim Chong Sun 531 Reputation points
2021-04-22T07:13:06.447+00:00

I did a Invoke-ADFSFarmBehaviorLevelRaise to raise my ADFS FBL from 1 to 3.

I got a Warning: Failed to add service account xxx to Enterprise Key Admin Group. Add the service account to the Enterprise Key Admin group.

The FBL raise is listed as successful.

Can I check if this warning is because I use a normal service account instead of gMSA?
And what happens if I don't add the service account to Enterprise Key Admin Group.

Microsoft Security | Active Directory Federation Services
0 comments No comments
{count} votes

Accepted answer
  1. Pierre Audonnet - MSFT 10,191 Reputation points Microsoft Employee
    2021-04-22T20:51:07.907+00:00

    The Enterprise Key Admin group membership is required if you need to use Windows Hello for Business with ADFS and the Certificate Trust.
    If you do not plan to use this, you can ignore the message and go on :)

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.