Solved

403. Access Denied after ADFS migration

Posted on 2014-01-11
8
1,465 Views
Last Modified: 2014-02-05
Hello all,

I have completed an ADFS migration from a WIndow server 2008 ENterprise R2 to WIndows SErver 2012 STandard. I performed an in place upgrade, restore and configure the ADFS services.

I have followed Microsoft preparation and migration instructions but it is obvious that I am missing something.

AFter migration, my users were being prompted constantly for credentials on their Outlook client. Also when trying to log into the Office 365 portal, they are unable to authenticate to it, they are instantly redirected to an access denied error as soon as they type their email address. The error is: "403 Forbidden- Access Denied. You do not have permission to view this directory or page with the credentials you provided."

It will be good to mention that before migration, when trying to log into the portal, our users were prompted by our adfs for credentials, but now it redirect us straight to the Access Denied error describe.

Any help on this will be greatly appreciated!
0
Comment
Question by:LuiLui77
  • 4
  • 4
8 Comments
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39773869
Update the trust settings, as described here:

http://support.microsoft.com/kb/2647048

If it's still not working, check if this happens for both internal and external users. Do the tests on ExRCA: https://testconnectivity.microsoft.com/
0
 

Author Comment

by:LuiLui77
ID: 39779244
Hello Vasilcho, I was able to revert to the functional ADFS. Thank God I had a DR planned. The upgraded ADFS vm is up but disconnected at the meantime we figure out this issue.

Checking on the certificates of the new ADFS I have found a discrepancy. The information for the Token-Decryption and the Token signing don't match with the certificates that I had on my original server.

Should I try to recreate and apply this certificates first before updating the trust settings?

What do you think?
0
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39779577
The cmdlet will update the trust with the correct certificate info. If you are using self signed certificates for token signing/issuing, might be a good idea to set it to auto-renew. It's explained in the article above.

If it's still not working after updating the trust, we need to check few more things.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:LuiLui77
ID: 39790243
Hi Vasilcho,

I am planning my DR in case anything goes wrong. To proceed with the cmdlet I will have to turn back on my snapshot that has the upgrade to 2012 and disconnect my current 2008 DR clone (the one currently working).

Now, when issuing the cmdlet on the 2012, and assuming that things don't go too well, I am planning to turn back on my old snapshot with 2008, but since the certificates configuration will be now outdated (since I issued the update federation cmdlet in the new one), what will be my DR plan?

I believe that I will be able to resync federation again with my 2008 by issuing the same cmdlet, but correct me if i am missing something.

I also believe that trust relationship with the DC will fail, so I will have to change the machine password on my DR snapshot as well, but this is another story.

Any help on what to include in my DR plan will be great.
0
 
LVL 40

Expert Comment

by:Vasil Michev (MVP)
ID: 39790329
If you are simply replacing the server, basically you are building a new farm. And the new certificates and settings you have there will result in different configuration, that you need to sync with O365.

A better approach will be to bring up additional server to the farm, verify connectivity, set it as primary, and then remove the old one. In such scenario, you will not need to update the trust settings, as the certificates and the rest of the configuration will be the same.

Of course in such scenario you will need to have at least one active ADFS server. You *should* be running at least two AD FS servers for redundancy anyway. In case of a disaster, you just bring another one to the farm. There is lot of info regarding this, for example here:

http://community.office365.com/en-us/forums/613/t/44639.aspx
0
 

Author Comment

by:LuiLui77
ID: 39791181
Yeah that's the thing.
My ultimate purpose is to create a farm between my on-premises ADFS server and my DR cloud server, the thing is that in order to create a farm, both servers will need to have the same version OS (as stated by Office 365 support, correct me if you know that this is not necessary). My cloud server is a Windows Standard 2012 and this was why I performed an in-Place upgrade of my on-premises ADFS server from 2008 R2 to 2012.

I believe that to setup and transfer over the ADFS role to a new server 2012 from scratch will be more time consuming and will involve more downtime.

With all this in mind, Do you think that my best DR option is to connect back my old snapshot and issue the same update federation cmdlet on it?
0
 
LVL 40

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 39791255
I don't think you must use the exact same OS version, support agents are delirious as usual. Even the official technet documentation supports this:

http://technet.microsoft.com/en-us/library/jj648428.aspx#BKMK_2

If you simply upgrade all nodes in a farm one by one, you shouldn't need to update the trust settings later. If you only have a single server and update it, either export/import the token certificates as well or better, run the update cmdlet afterwards.
0
 

Author Comment

by:LuiLui77
ID: 39837552
Thank you Vasilcho, I will be Updating the Federation with the cmdlet.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office Picture Manager was included in Office 2003, 2007, and 2010, but not in Office 2013. Users had hopes that it would be in Office 2016/Office 365, but it is not. Fortunately, the same zero-cost technique that works to install it with …
Veeam Backup & Replication has added a new integration – Veeam Backup for Microsoft Office 365.  In this blog, we will discuss how you can benefit from Office 365 email backup with the Veeam’s new product and try to shed some light on the needs and …
In a previous video Micro Tutorial here at Experts Exchange (http://www.experts-exchange.com/videos/1358/How-to-get-a-free-trial-of-Office-365-with-the-Office-2016-desktop-applications.html), I explained how to get a free, one-month trial of Office …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question