[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

ADFS 2.0 migration from 2008 R2 to 2012

Posted on 2014-02-07
5
Medium Priority
?
804 Views
Last Modified: 2014-02-13
Hello all, This one I have posted before but here we go again:

I have completed an ADFS migration from a WIndow server 2008 ENterprise R2 to WIndows SErver 2012 STandard. I performed an in place upgrade, restore and configure the ADFS services.

I have followed Microsoft preparation and migration instructions but it is obvious that I am missing something.

AFter migration, my users were being prompted constantly for credentials on their Outlook client. Also when trying to log into the Office 365 portal, they are unable to authenticate to it, they are instantly redirected to an access denied error as soon as they type their email address. The error is: "403 Forbidden- Access Denied. You do not have permission to view this directory or page with the credentials you provided."

I have updated trust successfully by issuing cmdlet: Update-MsolFederatedDomain -DomainName Domain.com. Checked on the logs and everything seems to have updated properly.

Any other advises on what to check next?
0
Comment
Question by:LuiLui77
  • 4
5 Comments
 

Author Comment

by:LuiLui77
ID: 39843629
OK, in IIS i have changed the ADFSAppPool from .NETFramwork v4.0 to v2.0. Now when I try to sign into the portal, a popup for credentials is prompted, which is a good sign, but after 3 retries with my known good password, it redirects me to the same error.

Any thoughts?
0
 

Author Comment

by:LuiLui77
ID: 39843638
Sorry error message is now:

401 - Unauthorized: Access is denied due to invalid credentials

Thank you.
0
 
LVL 45

Accepted Solution

by:
Vasil Michev (MVP) earned 2000 total points
ID: 39843820
Check your auth methods on IIS, make sure anonymous is enabled on both /adfs and /ls.

Can you login locally using AD FS? The url should be something like: https://sts.domain.com/adfs/ls/idpinitiatedsignon.aspx
0
 

Assisted Solution

by:LuiLui77
LuiLui77 earned 0 total points
ID: 39844147
Hi Vasilcho, I checked on the IIS authentication method and changed them to anonymous.

Also I installed Microsoft updates and when restarting the machine, "Trust between the machine and DC failed". Must have been related to a snapshot of the VM at some point.
I reset the machine password with netdom, restart again and everything started working.

ADFS is now up and running the way it should be.

Thank you for help Vasilcho!
0
 

Author Closing Comment

by:LuiLui77
ID: 39855698
Also I installed Microsoft updates and when restarting the machine, "Trust between the machine and DC failed". Must have been related to a snapshot of the VM at some point.
I reset the machine password with netdom, restart again and everything started working.
0

Featured Post

Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You have missed a phone call. The number looks like it belongs to the bunch of numbers which your company uses. How to find out who has just called you?
Here is a method which can be used to help resolve a "Content Index Failed" error on a Microsoft Exchange Server.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Suggested Courses

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question