Symptoms—When end users attempt to access the Forefront UAG portal, they may receive the following message "An authentication error occurred when signing in." There may also be an event 176 in the event viewer or in the Web Monitor with the description "ADFSv2Site: Found more than one claim with lead user name claim type [user_name_claim_type], Session ID: [session_ID], Trunk name: [trunk_name]."
Cause—If your AD FS 2.0 server sends more than one claim with the claim type that is used for the lead user value, users will be unable to sign in to the portal because Forefront UAG can accept only one claim of the claim type used for the lead user.
Solution—To change the claim types provided by the AD FS 2.0 server:
Ed Price MSFT edited Original. Comment: Updated the title case.
James Kilner edited Revision 1. Comment: No need for title case