Solved

ADFS 2.0 migration from 2008 R2 to 2012

Posted on 2014-02-07
5
745 Views
Last Modified: 2014-02-13
Hello all, This one I have posted before but here we go again:

I have completed an ADFS migration from a WIndow server 2008 ENterprise R2 to WIndows SErver 2012 STandard. I performed an in place upgrade, restore and configure the ADFS services.

I have followed Microsoft preparation and migration instructions but it is obvious that I am missing something.

AFter migration, my users were being prompted constantly for credentials on their Outlook client. Also when trying to log into the Office 365 portal, they are unable to authenticate to it, they are instantly redirected to an access denied error as soon as they type their email address. The error is: "403 Forbidden- Access Denied. You do not have permission to view this directory or page with the credentials you provided."

I have updated trust successfully by issuing cmdlet: Update-MsolFederatedDomain -DomainName Domain.com. Checked on the logs and everything seems to have updated properly.

Any other advises on what to check next?
0
Comment
Question by:LuiLui77
  • 4
5 Comments
 

Author Comment

by:LuiLui77
ID: 39843629
OK, in IIS i have changed the ADFSAppPool from .NETFramwork v4.0 to v2.0. Now when I try to sign into the portal, a popup for credentials is prompted, which is a good sign, but after 3 retries with my known good password, it redirects me to the same error.

Any thoughts?
0
 

Author Comment

by:LuiLui77
ID: 39843638
Sorry error message is now:

401 - Unauthorized: Access is denied due to invalid credentials

Thank you.
0
 
LVL 40

Accepted Solution

by:
Vasil Michev (MVP) earned 500 total points
ID: 39843820
Check your auth methods on IIS, make sure anonymous is enabled on both /adfs and /ls.

Can you login locally using AD FS? The url should be something like: https://sts.domain.com/adfs/ls/idpinitiatedsignon.aspx
0
 

Assisted Solution

by:LuiLui77
LuiLui77 earned 0 total points
ID: 39844147
Hi Vasilcho, I checked on the IIS authentication method and changed them to anonymous.

Also I installed Microsoft updates and when restarting the machine, "Trust between the machine and DC failed". Must have been related to a snapshot of the VM at some point.
I reset the machine password with netdom, restart again and everything started working.

ADFS is now up and running the way it should be.

Thank you for help Vasilcho!
0
 

Author Closing Comment

by:LuiLui77
ID: 39855698
Also I installed Microsoft updates and when restarting the machine, "Trust between the machine and DC failed". Must have been related to a snapshot of the VM at some point.
I reset the machine password with netdom, restart again and everything started working.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Microsoft Office Picture Manager was included in Office 2003, 2007, and 2010, but not in Office 2013. Users had hopes that it would be in Office 2016/Office 365, but it is not. Fortunately, the same zero-cost technique that works to install it with …
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question