Solved

ADFS 3.0 and UPN Problem

Posted on 2016-11-22
6
167 Views
Last Modified: 2016-11-24
I will do my best to describe our setup.

Windows 2012 R2 ADFS Proxy in the DMZ and one Windows 2012 R2 ADFS internal server. Our default UPN for all users is @child.domain.com (which is the name of our internal domain holding all user accounts) we are piloting o365 right now and about 50 users had to have their UPN's updated to @domain.com.  When these users try to access a host site that is setup on our ADFS server they are not able to authenticate. This worked perfectly up until their UPN was changed.

Question: how can I setup ADFS to have select user get authenticated using a different UPN than our default one.
0
Comment
Question by:compdigit44
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 41

Expert Comment

by:Adam Brown
ID: 41897925
I ran into this before a while back. The problem ended up being caused by the users' cached credentials. Basically, disable credential caching on the ADFS server and it should resolve the issue for you. http://nerdsknowbest.blogspot.com/2013/04/how-to-disable-credential-caching-in.html 
Let me know if it doesn't, though. It's been about 3 years since I ran into this issue, so I may be remembering the fix incorrectly (Another cause may be that the application you are authenticating to is using the old UPN as an identifier for the users, which would mean the user accounts in the application itself need to be modified to reflect the UPN change).
0
 
LVL 20

Author Comment

by:compdigit44
ID: 41898046
Thank you for the feedback. I am not the greatest in ADFS so please bare with me.

So if our domain is child.domain.com and users default UPN is child.domain.com but we switch a hand full of users to domain.com this does not make a difference in ADFS?  

Where would I find this caching setting you are talking about?
0
 
LVL 20

Author Comment

by:compdigit44
ID: 41898439
Thank you for the tip you gave to me earlier.... After further research a I came around the following KB about disabling cahcing on the ADFS servers. What is the downside of doing this?

https://support.microsoft.com/en-us/kb/2535191
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 41

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 41899045
The only downside is that users won't be able to log in if the ADFS server loses communication with a Domain Controller. That's generally a rare event, so it usually won't make a difference to disable credential caching in ADFS. In some ways it's actually preferable, since it ensures ADFS contacts a DC for each login.
0
 
LVL 20

Author Comment

by:compdigit44
ID: 41899858
Great thanks can you point me to documentation that states this which I could provide to my management as backup proof so they do not think I am making this up since by default ADFS caches credentials
0
 
LVL 41

Expert Comment

by:Adam Brown
ID: 41900993
It's not actually ADFS caching the credentials. It's the Windows LSA system doing it. It's basically the same credential caching that happens when you log in to any windows system. If you look up windows credential caching you can get a good explanation of what goes on. The registry setting here is just modifying the number of credentials cached to 0.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happenā€¦
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlleā€¦

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question