1,226 questions with Active Directory Federation Services tags

Sort by: Updated
5 answers One of the answers was accepted by the question author.

ADFS 2016 - Bypass Login Page using Local Claims Provider

Hello, I am on ADFS 2016 and I would like to bypass ADFS login page and use RESTful API to authenticate users stored in an LDAP Directory (Declared as Local Claims Provider). SAML 2.0 : apparently not possible to use REST API. =>Can you…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-04-21T16:15:56.28+00:00
Cedric D 131 Reputation points
accepted 2020-06-15T07:49:54.5+00:00
Cedric D 131 Reputation points
1 answer One of the answers was accepted by the question author.

Deny Administrators Login to the ADFS page

Is it possible to deny Administrators Login ADFS because I do not want anyone outside the network to guess the Administrators' password of my domain instead of Access Control Policy? (Because I found that only denies the users cannot sign on to another…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-03-28T18:58:38.957+00:00
Hau Kit Wong 71 Reputation points
commented 2020-06-13T17:43:11.383+00:00
Hau Kit Wong 71 Reputation points
1 answer One of the answers was accepted by the question author.

Can I custom other webpage in ADFS?

I know that I can custom the ADFS login page and I have done my customization. Still, I want to ask can I custom other webpages, especially the page when the user login successfully (like the picture that I attach). Thanks for your help!

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-11T16:42:00.1+00:00
Hau Kit Wong 71 Reputation points
accepted 2020-06-13T14:50:28.403+00:00
Hau Kit Wong 71 Reputation points
1 answer

Password reset does not stop access if valid MFA token

Using MFA Server with ADFS Adapter If a MFA enabled user changes their password, email is still accessible on phone without having to change password, assuming until token expires. I have read with Azure AD the refresh token would require the device…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
asked 2020-06-09T16:35:27.99+00:00
Robert Cook 1 Reputation point
commented 2020-06-12T21:00:35.917+00:00
Saurabh Sharma 23,791 Reputation points Microsoft Employee
2 answers

ADFS 4.0 on 2019, Device Registration Service - deleted Relying Party Trust

I am really struggling with this one. I installed ADFS 4 on 2019 (yes, 2019 forest and domain levels), topology is one back-end federation server for the farm, one database server (SQL, not WID). Haven't even setup the WAP yet...was playing with Device…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-09T23:55:56.65+00:00
wizardberry 1 Reputation point
answered 2020-06-12T01:25:21.827+00:00
wizardberry 1 Reputation point
1 answer One of the answers was accepted by the question author.

Migrating server to another network

Hi, I need to change the IP of the server that has the function of ADFS only. Are there any problems? Thank you.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-11T23:05:20.91+00:00
Salves 501 Reputation points
commented 2020-06-11T23:30:54.817+00:00
Salves 501 Reputation points
1 answer One of the answers was accepted by the question author.

Looking for the best solution to integrate azure AD with on-prem and other subsidiaries to share teams, calender, sharepoint online.

we have our AD domain in azure for example as abc.com with on-prem as abc.local, we want to connect for single sign on. Also looking for a solution to connect other subsidiaries for example def.com, xyz.com etc to share teams, calendar, sharepoints with…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
asked 2020-06-08T22:30:41.443+00:00
BN04 21 Reputation points
accepted 2020-06-09T12:44:39.587+00:00
BN04 21 Reputation points
0 answers

ADFS External access - new and trying to find some guides/guidance

For the most part I have ADFS working when accessed internally. However the main purpose for us implementing ADFS was for external access. We want to have ADFS be the primary authentication method for employees who have no VPN, or access to the domain…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-01T15:03:16.713+00:00
Jesse Hall 1 Reputation point
commented 2020-06-08T20:49:32.64+00:00
Jesse Hall 1 Reputation point
1 answer One of the answers was accepted by the question author.

Web Application Proxy with IIS client certificate authentication behind

Dear all, I have running a WAP (Server 2019) and an IIS (10.0). On IIS, a website is running, https://te.contoso.com/. A subfolder (te.contoso.com/subfolder) is protected by one-to-one client certificate authentication. This is working fine, as…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-04T18:08:03.78+00:00
Christoph Thurnheer 81 Reputation points
commented 2020-06-06T19:58:36.113+00:00
Christoph Thurnheer 81 Reputation points
1 answer One of the answers was accepted by the question author.

Certificate trust validation failed

After running the Microsoft Remote Connectivity Analyzer, we received a connectivity test fail while testing the certificate: Testing the SSL certificate to make sure it's valid. The SSL certificate failed one or more certificate validation…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-03T18:57:42.127+00:00
Rodrigo Rocha 96 Reputation points
accepted 2020-06-05T19:42:39.727+00:00
Rodrigo Rocha 96 Reputation points
2 answers One of the answers was accepted by the question author.

Federating and synchronising verified domain with existing AAD user accounts

We currently have two verified domains in our tenant. One is the primary UPN suffix in our onsite Active Directory and is already synchronised with AAD Connect and federated with ADFS. Now we want to do the same with the second domain - synchronise and…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,629 questions
asked 2020-06-05T07:17:48.41+00:00
Håvid Asgaut Falch 21 Reputation points
accepted 2020-06-05T09:47:08.393+00:00
Håvid Asgaut Falch 21 Reputation points
1 answer

Azure AD sync with multiple on-premp from differnet location

I have an on-prem AD called local.aa.com & an Azure O365 users aa.com, not synced. we are merging with different organizations, ab.com, ac.com, ad.com, they all have on-prem AD and O365 users. We need to federate or create a trust so all the AD…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-04T05:38:15.077+00:00
Bijo 1 Reputation point
answered 2020-06-04T08:01:25.483+00:00
Leon Laude 85,726 Reputation points
1 answer

Pass windows credentials through ADFS for external site without being prompted??

im running into an issue with passing logged in user credentials through internal ADFS to external website without being prompted for credentials. I added the site into the trusted sites, set the "automatic logon with current username and…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-06-02T18:59:39.903+00:00
Hall Jr, Rodney 1 Reputation point
commented 2020-06-03T20:00:51.42+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
2 answers

Migrate Relay Party to ADSF 2012 to 2019

HI Guys, I have almost 350+ RP configured in adfs 2012. I'm migrating all Relay Party from ADFS 2012 to 2019. Configuring this manually on 2019 its taking long time. old and new are different farm. can anyone help me with adfs have any migrate…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-26T08:00:40.67+00:00
Gopi Ponnusamy 41 Reputation points
answered 2020-06-02T17:07:21.93+00:00
Gopi Ponnusamy 41 Reputation points
1 answer One of the answers was accepted by the question author.

I keep getting errors while customizing ADFS

I'm trying to customize an ADFS (Windows Server 2019) server that won't take any of the command I give it. I'm using the exact same commands I've used to customize these pages with the same files even from the same locations but now it won't take them,…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-30T21:19:19.247+00:00
Vita 76 Reputation points
commented 2020-05-31T13:04:24.31+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
2 answers

ADFS Error upon logout (SAML)

Is there any difference between what ADFS and Azure support with respect to logout requests (is there a configuration on the ADFS side that needs to be set, does the SAML request need to include/exclude/get signed/etc. when sending to ADFS vs. Azure)?

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-28T23:12:40.94+00:00
Nitzan Harel 1 Reputation point
commented 2020-05-31T07:30:34.62+00:00
Nitzan Harel 1 Reputation point
1 answer One of the answers was accepted by the question author.

ADFS - initiate a connexion without using IdInitiatedSignon.html

Hello, I'd set up a relying party with an external webapp and I'd like to know if it's possible to connect the webapp (which I send the claims to) without using the https://adfs.internal.com/adfs/ls/idpinitiatedsignon.html which allows me to select…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-29T11:33:28.367+00:00
Louis DA SILVA 21 Reputation points
commented 2020-05-29T14:39:13.287+00:00
Louis DA SILVA 21 Reputation points
2 answers One of the answers was accepted by the question author.

List of ADFS proxies

Is there a way to get a list of proxies added to the ADFS server? For instance a PowerShell cmdlet like Get-AdfsProxyList? Use case - admin who set these up no longer works here.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-26T15:05:38.177+00:00
joym8 86 Reputation points
accepted 2020-05-28T17:15:31.49+00:00
joym8 86 Reputation points
1 answer

ADFS woes with .local domain and getting around it on 2016 servers.

Ive inherited a domain set up as abc.local Within the domain are many, many services and applications. The exchange is onsite and very few but growing cloud presence. Changing the domain from abc.local to an outside domain such as abc.com isnt…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-15T11:11:09.24+00:00
Thomas Bartram 1 Reputation point
answered 2020-05-28T13:08:08.133+00:00
Pierre Audonnet - MSFT 10,171 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Relying Party SAML logout request not logging out user from their portal

We have an ADFS 4 server and a proxy server, and about 10 relying parties set up for various software vendors. After importing a new relying party metadata file into ADFS, the relying party properties in ADFS show empty Signature and Encryption…

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,226 questions
asked 2020-05-23T21:30:25.453+00:00
joym8 86 Reputation points
accepted 2020-05-26T11:27:14.073+00:00
joym8 86 Reputation points