1,204 questions with Active Directory Federation Services tags

Sort by: Updated
1 answer

Convert my federated identity to standard

I setup my tenant with a Lab for federation and now the lab server no longer exists. I need to change my tenant back to standard. I tried to follow this article. https://gallery.technet.microsoft.com/office/Convert-MsolDomain-To-ced5a502 Thanks

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,748 questions
asked 2020-06-29T17:23:40.727+00:00
Thor Fayad 1 Reputation point
answered 2020-06-30T16:22:42.723+00:00
Shashi Shailaj 7,581 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

ADFS 2012R2 Claims that map from LDAP to SAML2 output not always clear

I'm trying to create a claim issuance policy. One of the mappings has to be the user SID. When I use the Get-ADUser powershell cmdlet I can see the User SID property is "SID", but when I try to find that in the list of pre-defined LDAP menu…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-26T23:15:41.013+00:00
Mike Murphy 41 Reputation points
accepted 2020-06-29T15:07:21.193+00:00
Mike Murphy 41 Reputation points
3 answers

ADFS SSL Renewal

So I am very new to AD FS and have been dropped in it. I have an SSL Cert that is going to expire in 7 days time. The production System has 2 AD server with FS on and 2 Proxy Server. I have created a test plaform that mimics the production as best I can…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-26T12:20:49.203+00:00
Chris Farmer 36 Reputation points
commented 2020-06-29T14:53:44.133+00:00
Chris Farmer 36 Reputation points
1 answer One of the answers was accepted by the question author.

Features and packages in Windows server 2019

With the help of the dism command and the /Get-Features switch I got a list of features and packages that are enabled or disabled in my installation. Is there any link that explains what these features do? (e.g. feature name: Tpm-PSH-Cmdlets). I…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-29T05:54:18.017+00:00
accepted 2020-06-29T08:29:14.82+00:00
0 answers

ADFS and MFA in Microsoft Browsers

Hi I'm after some help or suggestions as to what could be causing some odd behaviour in ADFS. A little background first. We have 2 WAP severs sitting in front of 2 ADFS servers which cal on 2 third party MFA severs, in our case Securenvoy. I'm using…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-23T12:47:05.08+00:00
Barry Pain 1 Reputation point
commented 2020-06-27T16:46:42.717+00:00
Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
1 answer

Lock Down Relying Party based on AD Attribute, Title

Hi All, We are using the ADFS 3.0. please help me. As the title states, is it possible to lock down a relying party based on an attribute value a user has in AD? For example, Our object is to Deny if the user's Title attribute value contains the…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-26T18:05:10.277+00:00
RAVI BABU CHIGURUSETTI 1 Reputation point
answered 2020-06-27T14:41:22.92+00:00
Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
2 answers

Can ADFS store and return user profile info upon login?

I am trying to connect my node.js application to ADFS, so that when a user logins in through ADFS it sends me the user's details (like whether he is an Admin, a regular user, or a privileged user). Can someone tell me if ADFS offers to store custom user…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,748 questions
asked 2020-06-23T16:54:42.463+00:00
Chris Darakjian 1 Reputation point
answered 2020-06-26T19:34:22.14+00:00
Sander Berkouwer 166 Reputation points
1 answer

Windows Application Proxy Server 2016 SSL Termination - CAN YOU TURN IT OFF??

Good Afternoon, My question is pretty simple. I'm just wondering if when using Windows Server 2016 Web Application Proxy to publish applications is there anyway to stop the WAP from doing SSL terminations (and rebuild) and just pass the traffic…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-09T16:56:30.987+00:00
BigPleyRay 1 Reputation point
commented 2020-06-26T13:01:59.93+00:00
Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
2 answers

Problem adfs farm

Hello, They could help me, I have a problem in farm adfs, I have a primary and a secondary adfs and they are in a Microsoft NLB, when I restart my primary adfs the entire authentication environment falls, I validated all certificates in the adfs and…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-22T21:41:02.323+00:00
Alan Ferreira Maia 26 Reputation points
answered 2020-06-24T17:40:04.383+00:00
Alan Ferreira Maia 26 Reputation points
1 answer One of the answers was accepted by the question author.

ADFS (WAP) not recoginzing/handling as internal traffic

Have a WAP with ADFS (4.0). All traffic (internal and external) is going through the same WAP. The internal traffic is not recoginized as such. If I change the autehntication mode internally to certificate and WIA only, it still shows me the form…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-23T08:02:10.21+00:00
Christoph Thurnheer 81 Reputation points
accepted 2020-06-23T13:34:53.903+00:00
Christoph Thurnheer 81 Reputation points
2 answers One of the answers was accepted by the question author.

Azure free account upgrade

I can,t upgrade for continued access to Azure my free Azure account

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-23T08:14:22.833+00:00
Wlodzimierz Wojtasiak 106 Reputation points
commented 2020-06-23T09:07:11.283+00:00
Leon Laude 85,676 Reputation points
1 answer

can i build and manage the adfs, not using Azure ad??

can i build and manage the adfs, not using Azure ad?? I do not want to use Azure AD just wanna On-premise adfs

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-22T07:23:35.587+00:00
choigeunchang 1 Reputation point
answered 2020-06-22T07:32:07.9+00:00
T. Kujala 8,706 Reputation points
2 answers One of the answers was accepted by the question author.

ADFS Custom rule: Send Value based on OU membership

We are a community college and I want to make a custom rule in ADFS based on OU membership. This rule must send out value 'Employee' or 'Student' based on the OU the account is located in. I can't use AD groups because there isn't any group…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-03-20T07:36:51.45+00:00
Ron 26 Reputation points
commented 2020-06-19T08:29:55.07+00:00
Ron 26 Reputation points
2 answers

Can't sign-in through ADFS when ExtranetLockout is enabled

I have two AD forests with two-way trust (selective authentication): prod.com and clients.com. Schemas in both forests were updated to Windows 2019 by adprep. There are ADFS and WAP servers with Windows 2019 in prod.com. (Upgraded from Windows…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-15T19:51:44.397+00:00
Ivan Doskochynskyi 21 Reputation points
commented 2020-06-17T15:34:11.677+00:00
Ivan Doskochynskyi 21 Reputation points
1 answer

.NET Mvc app with MS Azure Authentication refresh

've integrated the Azure authentication in an MVC application via Owin libraries. HttpContext.Current.GetOwinContext().Authentication.Challenge( new AuthenticationProperties { RedirectUri = baseurl + "Login/Index", AllowRefresh = true…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,748 questions
asked 2020-06-16T08:34:59.207+00:00
Francesco Ancona 1 Reputation point
answered 2020-06-16T12:15:23.583+00:00
Leon Laude 85,676 Reputation points
1 answer

Changing ADFS 3.0 service account (Server 2012 R2)

There are many post on how to change the service account by using the following script: ADFS3.xChangeSvcAcct.ps1 https://gallery.technet.microsoft.com/scriptcenter/Active-Directory-ddb67df0#content However, what I do not think is clear is how to…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-03-31T14:18:15.857+00:00
Max V 1 Reputation point
commented 2020-06-16T10:32:44.057+00:00
Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

New to ADFS (setup/diagram)

I am new to ADFS and I want to use one but don't know what the architecture would look like. For Internal use. Am I right to use this diagram? What ports are needed to communicate between the ADFS and DC? Do I need to use ADFS proxy for…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-07T08:29:41.917+00:00
Janus Bariñan 1,126 Reputation points
accepted 2020-06-16T06:48:58.633+00:00
Janus Bariñan 1,126 Reputation points
1 answer

ADFS for two forest with two way bi-directional trust

Hello Experts, I have a scenario, in which we have two seperate forests A and forest B. There is a two way bi-directional trust between them. I have ADFS in forest A and there are many relying party applications ( SAML based ) in forest A. I want…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-06-04T10:54:18.993+00:00
Parin 2 Reputation points
commented 2020-06-15T17:33:04.013+00:00
Parin 2 Reputation points
5 answers One of the answers was accepted by the question author.

ADFS 2016 - Bypass Login Page using Local Claims Provider

Hello, I am on ADFS 2016 and I would like to bypass ADFS login page and use RESTful API to authenticate users stored in an LDAP Directory (Declared as Local Claims Provider). SAML 2.0 : apparently not possible to use REST API. =>Can you…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-04-21T16:15:56.28+00:00
Cedric D 131 Reputation points
accepted 2020-06-15T07:49:54.5+00:00
Cedric D 131 Reputation points
1 answer One of the answers was accepted by the question author.

Deny Administrators Login to the ADFS page

Is it possible to deny Administrators Login ADFS because I do not want anyone outside the network to guess the Administrators' password of my domain instead of Access Control Policy? (Because I found that only denies the users cannot sign on to another…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,204 questions
asked 2020-03-28T18:58:38.957+00:00
Hau Kit Wong 71 Reputation points
commented 2020-06-13T17:43:11.383+00:00
Hau Kit Wong 71 Reputation points