Hi,
Preparing for ADFS migration from 2012R2 to 2019 I am trying to add a new WS 2019 node to ADFS farm running on WS 2012R2.
Join command completes with the error: Add-AdfsFarmNode : MSIS7711: PolicyOperationFault
This error is followed every 5 minutes by events 344:
There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.
Additional data
Exception details:
System.ServiceModel.Security.MessageSecurityException: The identity check failed for the outgoing message. The expected identity is 'identity(http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/spn)' for the 'http://adfs02.contoso.com/adfs/services/policystoretransfer' target endpoint.
and events 345:
There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.
Additional Data
Master Name : adfs02.contoso.com
Endpoint Uri : http://adfs02.contoso.com/adfs/services/policystoretransfer
Exception details:
System.ServiceModel.Security.MessageSecurityException: The identity check failed for the outgoing message. The expected identity is 'identity(http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/spn)' for the 'http://adfs02.contoso.com/adfs/services/policystoretransfer' target endpoint.
Infra background:
- AD: Windows 2012R2
- Forest & Domain functional model: Windows Server 2008 R2, prepared for Windows Server 2016
- ADFS OS version is Windows 2012R2 (Hyper-v VMs)
- ADFS is being implemented for Office 365 SSO plus other apps publishing.
- ADFS Plan: 2 ADFS Servers in Corporate LAN & 2 WAP Servers in DMZ. Both servers to be load balanced using HLB.
Troubleshooting done so far:
- Confirmed that both ws2012R2 nodes are syncing without any issue.
- Confirmed that test-adfsfarmjoin competed with success
- Confirmed that there is a dedicated domain user account with local admin permissions used while installing each server as ser service account.
- Confirmed that time & timezone are correct.
- Checked that the service account is correctly set with STS domain name.
- Checked that DNS names are correct
- Disabled Windows firewall.
- There is no other FW between ADFS nodes.
I have run out of ideas what is missing.
Kindly advise.
Thank you.
Regards, Pavel.