Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 772 other subscribers


  • LinkedIn
  • RSS Feed for Posts
  • Twitter
  • StumbleUpon

(Solved) Several ADFS tips and solutions

The last few months I’ve had several customers with ADFS problems.

I’ve decided to share the knowledge about these tips and solutions with you:

1 I Found a ADFS diagnostics module in the technet gallery:

AD FS Diagnostics Module

The AD FS Diagnostics Module contains commandlets to gather configuration information of an AD FS server, as well as commandlets to perform health checks to detect configuration issues based on common root causes identified during support engagements such as duplicate SPN, certificates not found, DNS records, etc.

Download the module

Place it in : C:\Windows\System32\WindowsPowerShell\v1.0\Modules\ADFSDiagnostics

Activate the module :

import-module adfsdiagnostics

2 Update the Service-Communications SSL certificate of ADFS and WAP servers

Changing the Service-Communications certificate for the Windows Server 2012 R2 ADFS servers and Windows Server 2012 R2 Web Application Proxy servers is sometimes tricky if you are not familiar with the technology.

Basically you need to perform 3 operations:

1. Change the Service-Communications certificate in ADFS.

2. Set the new SSL certificate to be used by the HTTP.sys driver.

3. Give to the ADFS service read access to the private key of the new certificate.

This script will do all of that.

3 Updating Windows Server 2012 R2 AD FS SSL and Service Certificates

This site explaines how to update the certificates on ADFS servers

4 HOW TO renew ADFS certificate on federation and WAP proxy server

HOW TO renew ADFS certificate on federation and WAP proxy server

5 ADFS WAP Error The operation stopped due to an unknown general error. Error code 0x8007520c

Unable to use the Remote Access Management Console, due to a problem with the certificate.

6 ADFS 3.0 > Unable to logon > “AADSTS50008: SAML token is invalid”

How to resolve Time sync issues

7 ADFS 3.0 Cannot start service MSSQL$MICROSOFT##WID

When you have problems installing ADFS

8 ADFS : Enable Single Sign-on (SSO) for Edge and Chrome browser

When you have problems, using Single Sign On in Edge of Chrome browsers

9 W2008R2 Error when federating a local domain to Office 365: The connection to Active Directory Federation Services 2.0 server failed due to invalid credentials.

Error federating ADFS server