Avatar of carlos soto
carlos soto
Flag for Sweden asked on

Sharepoint authentication cross forest

Hi

I have a domain (domain1.local) with adfs and sharepoint. I want to have some users that are part of another forest (domain2.local) authenticate through adfs to access sharepoint.
I have a full 2-way trust between the domains. Is there another configuration needed in the adfs side to get the authentication to work? I can add new claims and pinpoint to groups in the forest domain2.local, but i get the following error:
Encountered error during federation passive request.

Additional Data

Protocol Name:
Saml

Relying Party:
https://intranat.externaldomain.se 

Exception details:
Microsoft.IdentityServer.AuthenticationFailedException: testuser@domain2.local-The user name or password is incorrect ---> System.IdentityModel.Tokens.SecurityTokenValidationException: testuser@domain2.local ---> System.ComponentModel.Win32Exception: The user name or password is incorrect
Microsoft SharePoint* Active Directory Federation Services (ADFS)

Avatar of undefined
Last Comment
carlos soto

8/22/2022 - Mon
Alex

I have a domain (domain1.local) with adfs and sharepoint. I want to have some users that are part of another forest (domain2.local) authenticate through adfs to access sharepoint.


That's not indicative of another forest but another domain, can you please confirm?

Also, from my understanding you need to make sure that the UPN suffixes in each forest match the registered domain in Azure AD.
carlos soto

ASKER
hi alex

these are 2 different domains, in separate AD forest. These domains are not synchronized to Azure AD, they are only present locally.
So the scenario is:
user from dimain2.local authtenticates to adfs in domain1.local, to access sharepoint in domain1.local. In my understanding the adfs server, through a relaying party trust and a claim, should ask the domain controllers in domain2.local to verify the users credentials

am i wrong or am i missing something ?
br
Carlos
ASKER CERTIFIED SOLUTION
carlos soto

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy