Quantcast
Channel: Claims based access platform (CBA), code-named Geneva forum
Viewing all articles
Browse latest Browse all 2535

AD FS fails to get configured and start

$
0
0

Greeting

Greetings,

I have an 3 VM's running Windows Server 2012 R2 in a data center running on a common network, joined to the same domain. One of the VM's is running DirSync to synchronise to Office365, another is an AD DC (with a DNS server too) and the third does not matter... The AD is synced from a Windows server 2008 AD (which for ADFS should be fine).

I am trying to install AD FS for SSO with Office365. The tried both: on my Domain Controller VM and my DirSync VM (i know the advice not to have ADFS on either, but it should still function!). I used WID and not SQL. I've removed WID and the ADFS role, deleted the WID files too. Re-added it all... nothing

The role installs just fine. The configuration wizard for ADFS however fails. Starting the service manually also fails. No clear error message. Just says failed.

  1. Have a certificate from a root CA for fs.companyname.com which imports fine and allows to select the correct Federation Service Name. The DNS provider records have also been updated to point to the real IP where the 3 VM's are.
  2. Created an ADFS service account (with manually updating the SPN or letting the wizard do it - neither makes a difference)
  3. Have all the admin rights for the account I am using in AD.
  4. Added an An 'A' record to my DNS records (on the AD DC VM) for the subdomain i've issued teh certificate for (i.e. fs.example.com) pointing to the real IP (even tried the local one). It resolves just fine.

There is no clear event viewer entry about why it failed. It just says something like this from Service Control Manager: 

"The Active Directory Federation Services service terminated with the following error: 
An exception occurred in the service when handling the control request."


I've ran the same procedures on another sanbox VM with the same setup - it all worked out fine...

Please help. 3 days of banging my head on the wall... no results...

Thanks.

P.S. Some additional errors i've pasted here (in reverse order - i.e. the events occur from the bottom error up; I've also replaced my domain name with 'exampledomain').



Viewing all articles
Browse latest Browse all 2535

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>