Solved

Problem converting Office 365 domain to federated for ADFS 2.0

Posted on 2013-02-01
5
3,091 Views
Last Modified: 2013-05-17
Hello all,

I've been trying to get my organization switched over to Office 365.  We currently host our own Active Directory and Exchange 2010 servers on premise.  My plan is to fully setup ADFS 2.0 and a proxy to provide the authentication for our AD (we are going to disable the extended protection).

I've provisioned three servers thus far: two ADFS and one ADFS proxy.  I've already installed ADFS, a SQL Server instance, setup NLB, and connected the servers to SQL as a farm.  I've been trying to convert our (already verified) domain on Office 365 to be federated via PowerShell with the following command:

PS C:\Windows\system32> Convert-MsolDomainToFederated -DomainName example.com

Open in new window


The problem is that I'm getting a Microsoft.Online.Administration.Automation.IdentityInternalServiceException  The specifics are:

CategoryInfo : NotSpecified: (:) [Convert-MsolToFederated], FederationException
FullyQualifiedErrorId : Microsoft.Online.Administration.Automation.IdentityInternalServiceException,MicrosoftOnline.Identity.Federation.Powershell.ConvertDomainToFederated

Open in new window


Any help regarding this would be super helpful.  I'm really have a hard time getting this hybrid forest setup because of the ADFS and all that is involved.
0
Comment
Question by:jbcsystech
  • 2
  • 2
5 Comments
 
LVL 10

Expert Comment

by:justinoleary911
ID: 38844419
Where did you run the command Convert-MsolDomainToFederated?

If you are not running the command Convert-MsolDomainToFederated on your Active Directory Federation Services (ADFS) server , it is required to connect to the ADFS server first by running the following command:

Set-MsolADFSContext –Computer <AD FS 2.0 server name>

I suggest running the command Convert-MsolDomainToFederated on your ADFS server directly. For your reference, I provide the information about how to deploy Active Directory Federation Services 2.0 and configure Microsoft Online Services Module for Windows PowerShell as below:

Plan for and deploy Active Directory Federation Services 2.0 for use with single sign-on
http://onlinehelp.microsoft.com/en-us/Office365-enterprises/ff652539.aspx

Install and configure the Microsoft Online Services Module for Windows PowerShell for single sign-on
http://onlinehelp.microsoft.com/en-us/Office365-enterprises/ff652560.aspx
0
 

Author Comment

by:jbcsystech
ID: 38844671
Hello Justin,

Thanks for your quick response.  I've actually been following those guides you posted along with some others.  I ran the command from one of my ADFS servers, actually.  Now I have them setup as ADFS1 and ADFS2 with NLB.  I have SQL Server running on ADFS1.

Some of a guides I've been following for your reference:
http://www.stevieg.org/2012/05/configuring-ad-fs-2-with-tmg-based-sso-to-office-365/
http://jorgerdiaz.wordpress.com/2011/04/20/office-365-configuring-ad-fs/
http://blog.msresource.net/2011/05/23/deploying-a-federation-server-with-a-sql-database/
0
 
LVL 10

Accepted Solution

by:
justinoleary911 earned 500 total points
ID: 38844772
We actually had a customer with this issue and it was solved by changing the domain password policy to the default one:

Set-MsolPasswordPolicy -ValidityPeriod 90 -NotificationDays 14 -DomainName domain.com

let me know if this helps
0
 

Author Closing Comment

by:jbcsystech
ID: 38845027
That was it!  Thanks so much.
0
 

Expert Comment

by:Joel Parmer
ID: 39176134
Holy!  That would NEVER have crossed my mind but that did the trick.  Thanks!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Veeam Backup & Replication has added a new integration – Veeam Backup for Microsoft Office 365.  In this blog, we will discuss how you can benefit from Office 365 email backup with the Veeam’s new product and try to shed some light on the needs and …
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now