ADFS logon issue when logon from an external domain


hello!

i have following configuration:

domain testad.local, adfs 2.0 server installed

claims-aware application in other domain (lets production.com)

user accounts stored in ad in testad.local

when logon claim-aware application pc in testad.local domain - works fine

but if try logon application production.com domain logon failed , receive following errors:

1)in security log on adfs server

event 4625

account failed log on.

subject:
security id: null sid
account name: -
account domain: -
logon id: 0x0

logon type: 3

account logon failed:
security id: null sid
account name: vyunov
account domain: testad

failure information:
failure reason: an error occured during logon.
status: 0x80090302
sub status: 0xc0000418

process information:
caller process id: 0x0
caller process name: -

network information:
workstation name: wsm7
source network address: -
source port: -

detailed authentication information:
logon process: ntlmssp 
authentication package: ntlm
transited services: -
package name (ntlm only): -
key length: 0

2) in domain controller log in testad.local

event 4625

account failed log on.

subject:
security id: null sid
account name: -
account domain: -
logon id: 0x0

logon type: 3

account logon failed:
security id: null sid
account name: vyunov
account domain: production

failure information:
failure reason: unknown user name or bad password.
status: 0xc000006d
sub status: 0xc000006a

process information:
caller process id: 0x0
caller process name: -

network information:
workstation name: wsm7
source network address: 10.*.*.*
source port: 63030

detailed authentication information:
logon process: ntlmssp 
authentication package: ntlm
transited services: -
package name (ntlm only): -
key length: 0

i try logon testad\vyunov, testad.local\vyunov, vyunov@testad.local - same result! in security log on domain controller there production domain mentioned

don understand why..

could advise how resolve issue?

hello,

for ad fs http://social.msdn.microsoft.com/forums/en-us/geneva/threads/ better forum.


best regards

meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/

disclaimer: posting provided no warranties or guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group