TechNet
Products
IT Resources
Downloads
Training
Support
Products
Windows
Windows Server
System Center
Microsoft Edge
Office
Office 365
Exchange Server
SQL Server
SharePoint Products
Skype for Business
See all products »
Resources
Channel 9 Video
Evaluation Center
Learning Resources
Microsoft Tech Companion App
Microsoft Technical Communities
Microsoft Virtual Academy
Script Center
Server and Tools Blogs
TechNet Blogs
TechNet Flash Newsletter
TechNet Gallery
TechNet Library
TechNet Magazine
TechNet Wiki
Windows Sysinternals
Virtual Labs
Solutions
Networking
Cloud and Datacenter
Security
Virtualization
Updates
Service Packs
Security Bulletins
Windows Update
Trials
Windows Server 2016
System Center 2016
Windows 10 Enterprise
SQL Server 2016
See all trials »
Related Sites
Microsoft Download Center
Microsoft Evaluation Center
Drivers
Windows Sysinternals
TechNet Gallery
Training
Expert-led, virtual classes
Training Catalog
Class Locator
Microsoft Virtual Academy
Free Windows Server 2012 courses
Free Windows 8 courses
SQL Server training
Microsoft Official Courses On-Demand
Certifications
Certification overview
Special offers
MCSE Cloud Platform and Infrastructure
MCSE: Mobility
MCSE: Data Management and Analytics
MCSE Productivity
Other resources
Microsoft Events
Exam Replay
Born To Learn blog
Find technical communities in your area
Azure training
Official Practice Tests
Support options
For business
For developers
For IT professionals
For technical support
Support offerings
More support
Microsoft Premier Online
TechNet Forums
MSDN Forums
Security Bulletins & Advisories
Not an IT pro?
Microsoft Customer Support
Microsoft Community Forums
Sign in
Home
Library
Wiki
Learn
Gallery
Downloads
Support
Forums
Blogs
Resources For IT Professionals
United States (English)
Россия (Pусский)
中国(简体中文)
Brasil (Português)
Skip to locale bar
Get this Tag RSS feed
Translate this page
Powered by
Microsoft® Translator
Popular Tags
Active Directory
AD
AD DS
adfs
ASP.NET
azure
BizTalk
BizTalk Server
BizTalk Server 2010
C#
Candidate for deletion
certification
cloud
core docs
de-DE
EAA
Ed Price
Ed's Stub Pages
en-US
ESA
es-ES
Excel
Exchange
Exchange 2010
fa-IR
Fernando Lugao Veltem
FIM
FIM 2010
FIM Resources
FIM-HELP
forefront
forums
fr-FR
Gokan Ozcifci
has code
has comment
has comments
has image
has Images
has Other Languages
has See Also
Has Table
Has TOC
Horizon_Net
How To
Hyper-V
id-ID
IIS
Italian Wiki Articles
it-IT
ja-JP
Jordano Mazzoni
Link Collection
Luciano Lima
Luigi Bruno
Lync Server 2010
MIISILMFIM MACAULAY
Multi Language Wiki Articles
needs work
operations manager
Pirated Content
Portal
Português Brasil
PowerShell
pt-BR
security
SharePoint
SharePoint 2010
SharePoint 2013
SharePoint Pirate
Small Basic
solucionando problemas
SQL Server
SQL Server 2012
stub
System Center
System Center 2012
TechNet Guru
TechNet Wiki
TechNet Wiki Featured Article
tonyso
Translated into Japanese
troubleshooting
tr-TR
vídeo
Video
Virtualization
VMM
Wiki
Windows
Windows 7
Windows 8
Windows Azure
Windows Server
Windows Server 2003
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
yottun8
اکتیو دایرکتوری
Browse by Tags
>
TechNet Articles
>
All Tags
>
AD FS 2.0
Tagged Content List
Wiki Page:
AD FS 2.0: Dynamic Claim Types
Joji Oshima
Dynamic Claim Types There is data stored about a user in a SQL database ( or other attribute store ). The data stored about the user in the database needs to be a part of the claim type and not the value of the claim. For example, properties “ Redmond ” and “ Building3 ” stored in a database...
on
28 Feb 2013
Wiki Page:
AD FS 2.0: Using RegEx in the Claims Rule Language
Joji Oshima
An Introduction to Regex The use of RegEx allows us to search or manipulate data in many ways in order to get a desired result. Without RegEx, when we do comparisons or replacements we must look for an exact match. Most of the time this is sufficient but what if you need to search or replace based...
on
28 Feb 2013
Wiki Page:
AD FS 2.0: How to Consume RelayState to Automate Access to Relying Parties During IDP-Initiated Sign-On
Yagmoth555
“This article has been retired since a fix for this issue has recently been made available. For details about what RelayState issue was fixed, see Description of Update Rollup 2 for Active Directory Federation Services (AD FS) 2.0 or Supporting Identity Provider Initiated RelayState .”
on
23 Feb 2013
Wiki Page:
AD FS 2.0: How To Modify The Duration of AutoCertificateRollover Certificates
Yagmoth555
Overview By default in AD FS 2.0, the self-signed certificates generated by AutoCertificateRollover are valid for 365 days. Although AD FS 2.0 will maintain these certificates for the service, it is the responsibility of the AD FS 2.0 administrator or the Claims Proivder/Relying Party partner administrator...
on
23 Feb 2013
Wiki Page:
Forefront UAG Troubleshooting: Event ID 161: The User Name Claim Type Is Missing from the Security Token
Richard Mueller
Symptoms — When end users attempt to access the Forefront UAG portal, they may receive the following message " The request cannot be completed. User details are missing. Contact the site administrator. " There may also be an event 161 in the event viewer or in the Web Monitor with the description...
on
22 Feb 2013
Wiki Page:
AD FS 2.0: How to Automatically Add the AD FS 2.0 Powershell Snap-in When Launching Powershell
Richard Mueller
If you often administer your AD FS 2.0 Federation Service using PowerShell, there is an easy way to automatically add the AD FS 2.0 PowerShell snap-in when the PowerShell console window is launched. Ove rview PowerShell loads a profile for the user when the console window is launched. We...
on
22 Feb 2013
Wiki Page:
AD FS 2.0: "The request specified an Assertion Consumer Service URL that is not configured on the relying party"
Yagmoth555
Symptoms Sign-in fails The following events are logged in the AD FS 2.0/Admin event log: Log Name: AD FS 2.0/Admin Source: AD FS 2.0 Date: 07/28/2011 05:15:28 PM Event ID: 364 Level: Error User: CONTOSO\ADMIN Computer: adfs.contoso.com Encountered error during federation...
on
21 Feb 2013
Wiki Page:
AD FS 2.0: How to Migrate Claim Rules Between Trusts
Yagmoth555
Overview This article demonstrates how to migrate claim rules from one trust in AD FS 2.0 to another trust in AD FS 2.0. This may be useful when you are creating multiple trust relationships which will utilize similar claim rules, or when you are migrating configuration data between test, staging...
on
19 Feb 2013
Wiki Page:
AD FS 2.0: How to Use Fiddler Web Debugger to Analyze a WS-Federation Passive Sign-In
Yagmoth555
This article's purpose is to demonstrate how to utilize Fiddler Web Debugger to analyze traffic in a WS-Federation sign-in conversation, specifically for AD FS 2.0. If you are looking for Fiddler debugging information for another protocol such as WS-Trust or SAML 2.0, please see the More Information...
on
19 Feb 2013
Wiki Page:
Federation Extensions for SharePoint 3.0 - ID1013: "Could not access the server hosting the WS-Federation metadata document. Object Identifier (OID) is unknown."
Yagmoth555
Symptoms While executing Federation Extensions for SharePoint 3.0 on Windows Server 2003, the utility fails with the following error: ID1013: Could not access the server hosting the WS-Federation metadata document. Object Identifier (OID) is unknown Cause This is related to SHA2 support...
on
14 Feb 2013
Wiki Page:
AD FS 2.0: How to Request a Specific Name ID Format from a Claims Provider (CP) During SAML 2.0 Single-Sign-On (SSO)
Yagmoth555
When AD FS 2.0 is the Service Provider Security Token Service (STS) and is involved in SAML 2.0 passive web SSO, there may be a requirement from the CP (also known as Identity Provider or IDP) to have AD FS 2.0 instruct the CP as to which Name ID Format is required. SAML 2.0 protocol specifies an...
on
14 Feb 2013
Wiki Page:
AD FS 2.0: How to Change the Local Authentication Type
Yagmoth555
AD FS 2.0, out of the box, supports four local authentication types: Integrated Windows authentication (IWA) - can utilize Kerberos or NTLM authentication. You should always prefer Kerberos authentication over NTLM and configure the appropriate service principal name (SPN) for the AD FS 2.0 service...
on
6 Feb 2013
Wiki Page:
Windows Identity Foundation (WIF): How to Change Certificate Chain Validation Settings for Web Applications
Yagmoth555
Summary When you run FedUtil.exe or Federated Extensions for SharePoint 3.0, you have the option of turning on/off certificate chain validation for the token-signing certificate in the GUI. You may, however, decide at a later date that you wish you would have turned it off or maybe you need to...
on
6 Feb 2013
Wiki Page:
AD FS 2.0: Windows service does not start, does not start automatically, or starts slowly
Yagmoth555
Overview The AD FS 2.0 service takes a long time to start and restart The AD FS 2.0 service may fail to start upon login The AD FS 2.0 service may fail to start altogether The AD FS 2.0 server does not have outbound Internet access Disable Authenticode Signing Verification ...
on
5 Feb 2013
Wiki Page:
Active Directory Federation Services (ADFS) Wiki Articles
Richard Mueller
This page provides a quick overview of the Technet Wiki articles related to ADFS (Active Directory Federation Services). The Wiki search engine provides you with the latest updates, but it does not provide a comprehensive overview, nor the search results are grouped (yet). This page focusses on...
on
1 Jan 2013
Wiki Page:
Configuring TMG as an AD FS 2.0 Proxy
Richard Mueller
Table of Contents TMG vs the AD FS 2.0 proxy Basic setup of TMG 2010 Installing TMG 2010 Configure Network Settings Configure System Settings Define Deployment Options Configure Firewall Policy Configure Policy Validating Your Configuration Troubleshooting Alternate Configurations Listener Authentication...
on
2 Nov 2012
Wiki Page:
AD FS 2.0: Domain Local Groups in a claim
Joji Oshima
Introduction The basic method for adding group memberships into claims is using Send LDAP Attributes as Claims and picking one of the tokenGroups options. This method works for global and universal groups, but will leave out any domain local groups. The primary reason for this is there is no intuitive...
on
4 Oct 2012
Wiki Page:
AD FS 2.0 RelayState Generator
Joji Oshima
Introduction The ability to generate RelayState in AD FS 2.0 was added in Rollup 2. To do this you must run through the following process. URL Encode the relying party's identifier URL Encode the RelayState to send Take both values of both, and add them to this string: RPID= <URL...
on
23 Aug 2012
Wiki Page:
How to Enable Debug Logging for Active Directory Federation Services 2.0 (AD FS 2.0)
nzpcmad1
AD FS 2.0 uses Event Tracing for Windows (ETW) for debug logging. Configure AD FS 2.0 tracing Open the following file in a text editor: %ProgramFiles%\Active Directory Federation Services 2.0\Microsoft.IdentityServer.Servicehost.exe.config Locate the <system.diagnostics> tag...
on
9 Aug 2012
Wiki Page:
AD FS 2.0: How to Manually Run the AD FS 2.0 Initial Configuration
LeoPonti
Summary There may come a time when you need to run the Active Directory Federation Services ( AD FS) 2.0 Initial Configuration again and you might not want to have to reinstall AD FS 2.0 to get there. The AD FS 2.0 MMC prompts you to run the Initial Configuration one time after installation...
on
25 Jul 2012
Wiki Page:
AD FS 2.0: How to Capture A Log During Installation (AdfsSetup.exe)
LeoPonti
Summary Active Directory Federation Services (AD FS) 2.0 components for Federation Server and Federation Server Proxy are installed using AdfsSetup.exe from the Microsoft Download site. Various items are validated or installed during execution of AdfsSetup.exe, and a debug log might help you troubleshoot...
on
25 Jul 2012
Wiki Page:
AD FS 2.0: Event ID 47 is Logged in AD FS 2.0 Tracing/Debug with MSIS1022 and ID6008
Fernando Lugão Veltem
Table of Contents Symptoms Cause Resolution More Information Symptoms AD FS 2.0 is the Relying Party (RP) An error occurs while consuming a security token from a trusted Claims Provider (CP) The AD FS 2.0 Tracing/Debug log shows an event similar to the following: Log...
on
17 Jun 2012
Wiki Page:
Forefront UAG Troubleshooting: Event ID 176: Too Many Claims with the Lead User Name Claim Type
Fernando Lugão Veltem
Symptoms — When end users attempt to access the Forefront UAG portal, they may receive the following message " An authentication error occurred when signing in. " There may also be an event 176 in the event viewer or in the Web Monitor with the description " ADFSv2Site: Found more...
on
27 May 2012
Wiki Page:
Forefront UAG Troubleshooting: Event ID 151: User Could Not Be Signed In
Fernando Lugão Veltem
Symptoms — When end users attempt to access the Forefront UAG portal, they may receive the following message " An authentication error occurred when signing in. " There may also be an event 151 in the event viewer or in the Web Monitor with the description " WS-FAM: User with lead...
on
25 May 2012
Wiki Page:
AD FS 2.0: The Admin Event Log Contains Error Event 320. "MSIS1010: Signed SAML message must have Destination URI specified."
Fernando Lugão Veltem
Table of Contents Symptoms Cause Resolution Symptoms The following event is logged in the AD FS 2.0/Admin event log: Log Name: AD FS 2.0/Admin Source: AD FS 2.0 Date: 6/15/2011 6:06:40 PM Event ID: 320 Task Category: None Level: Error Keywords: AD FS User: S-1-5...
on
22 May 2012
Page 3 of 5 (102 items)
1
2
3
4
5
Can't find it? Write it!
Post an Article