ADFS logon issue when logon from an external domain
hello!
i have following configuration:
domain testad.local, adfs 2.0 server installed
claims-aware application in other domain (lets production.com)
user accounts stored in ad in testad.local
when logon claim-aware application pc in testad.local domain - works fine
but if try logon application production.com domain logon failed , receive following errors:
1)in security log on adfs server
event 4625
account failed log on.subject:
security id: null sid
account name: -
account domain: -
logon id: 0x0
logon type: 3
account logon failed:
security id: null sid
account name: vyunov
account domain: testad
failure information:
failure reason: an error occured during logon.
status: 0x80090302
sub status: 0xc0000418
process information:
caller process id: 0x0
caller process name: -
network information:
workstation name: wsm7
source network address: -
source port: -
detailed authentication information:
logon process: ntlmssp
authentication package: ntlm
transited services: -
package name (ntlm only): -
key length: 0
2) in domain controller log in testad.local
event 4625
account failed log on.subject:
security id: null sid
account name: -
account domain: -
logon id: 0x0
logon type: 3
account logon failed:
security id: null sid
account name: vyunov
account domain: production
failure information:
failure reason: unknown user name or bad password.
status: 0xc000006d
sub status: 0xc000006a
process information:
caller process id: 0x0
caller process name: -
network information:
workstation name: wsm7
source network address: 10.*.*.*
source port: 63030
detailed authentication information:
logon process: ntlmssp
authentication package: ntlm
transited services: -
package name (ntlm only): -
key length: 0
i try logon testad\vyunov, testad.local\vyunov, vyunov@testad.local - same result! in security log on domain controller there production domain mentioned
don understand why..
could advise how resolve issue?
hello,
for ad fs http://social.msdn.microsoft.com/forums/en-us/geneva/threads/ better forum.
best regards
meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/
disclaimer: posting provided no warranties or guarantees , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment