AD FS Logon Page Graphics

Two Planker 111 Reputation points
2021-10-13T20:20:22.99+00:00

Greetings,

I've deployed an AD FS server successfully in an isolated environment (no Internet). When I get to the AD FS logon page, there are no graphics, just text and related fields. I'm not having any luck finding a resolution. The system works properly otherwise.

Has anyone experienced this?

Thanks,

Chris

Windows for business | Windows Server | User experience | PowerShell
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Two Planker 111 Reputation points
    2021-11-16T17:07:03.313+00:00

    Sikumars,

    after breaking and troubleshooting ADFS after a backup, uninstall, re-install and restore, I have found a workaround here:

    https://social.technet.microsoft.com/Forums/Lync/en-US/2df3ef95-b0e1-4a89-96ce-3fd4edd7a7f9/failed-to-start-endpoint-https49443adfsportal?forum=ADFS

    I've added my Group Managed Service Account to the local admins group and now the graphics on the logon page appear. I've also tried the "fix" described by one of the users yet it does not work. Only adding the gmsa to the admins group allows the site to present normally.

    I may not be applying the fix properly as I don't quite understand all that he is referring to. I tried modifying the url acl permission for https://+:443/adfs by deleting the existing perms for User: NT SERVICE\adfssrv and adding my gmsa service account yet there was no change after restarting services.

    Does this make sense to you?

    I apologize if I don't reply to any responses as I'm leaving town for about a week.

    Thanks for the help,

    TP

    1 person found this answer helpful.

10 additional answers

Sort by: Most helpful
  1. Two Planker 111 Reputation points
    2021-11-16T17:15:02.7+00:00

    A quick update,

    I removed the gmsa account from the admin group and restarted the adfs server. The logon page graphics are still present. Wondering if the fix actually worked and the server just needed restarting or did adding/removing the gmsa account from the admin group was all that was needed.

    TP

    2 people found this answer helpful.

  2. Rich Matheisen 47,901 Reputation points
    2021-10-13T21:05:05.52+00:00
    0 comments No comments

  3. Limitless Technology 39,921 Reputation points
    2021-10-15T09:34:38.61+00:00

    Hi there,

    When a federated user tries to sign in to a Microsoft cloud service such as Office 365, Microsoft Azure, or Microsoft Intune, the Internet browser can't display the Active Directory Federation Services (AD FS) sign-in webpage. Additionally, the user may receive an error message.

    This issue may occur if the user can't contact the on-premises AD FS federation server or the Internet-facing AD FS Federation server proxy. This can occur when the AD FS Federation Service stops running or when IP connectivity is marginalized.

    You can try the following steps https://learn.microsoft.com/en-us/office365/troubleshoot/sign-in/ad-fs-sign-in-page-not-display

    ------------------------------------------------------------------------------------------------------------------------------------

    If the reply is helpful, please Upvote and Accept it as an answer


  4. VipulSparsh-MSFT 16,311 Reputation points Microsoft Employee
    2021-10-18T12:22:37.187+00:00

    @Two Planker Since you mentioned that you configured that in an isolated environment, make sure that the machine on which you are trying has the ADFS url in local intranet zone of internet explorer.

    Follow this if you need step by step method : https://learn.microsoft.com/en-us/dynamics365/customerengagement/on-premises/deploy/add-the-ad-fs-website-to-the-local-intranet-security-zone?view=op-9-1

    Let me know if this helps, we can also take this offline to understand more and help.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.