ADFS 2.0 Question about UPNs


i have question setting upn adfs. typically have used .local domain name joining machines. if want use routable domain have use non .local domain. understanding each user needs upn changed well? have added upn domain. however, when change user can no longer logon .local domain. way logon use user@newdomain.com username. required? solution tell users use username in future or re-join .com public routable domain?

 

thanks!

answer question posed th3j35t3r
==============
asking not possible due current configuration.
cannot have 2 domains same upn's (user principal name) contained in them unless in same forest.  because of name suffix routing works across trusts.  please reference technet article below in regard

 

answer question posted philjfry
==============

the upn (user principal name) has nothing domain name.  not need rename or rejoin users or computers.  upn's used kerberos authentication.
when user login occurs the login information goes kdc ldap search in own domain user principal name.  if cannot find upn locally search global catalog.  if upn found in global catalog routed proper kdc or if not sent tdo (trusted domain object) matches name suffix routing name suffix under active directory trust configuration.

please see following in regard routing name suffixes across forests -
http://technet.microsoft.com/en-us/library/cc784334%28ws.10%29.aspx

the issue can foresee running if 1 of users cached credentials happens users alternate user principal name value when attempt made use kerberos authentication has potential use upn format of users account name.  since value of upn stored in cached credential not same value stored in active directory kerberos authentication fail.

resolution
vista or higher clients computers:

1.  comptuer on corporate network have user logon workstation.
2.  users workstation connected corporate network (either directly or through vpn) have user lock workstation , unlock it.

for windows xp / windows server 2003 computers:

1. comptuer on corporate network have user logon workstation using upn name.  example:  bob@contoso.com
2. users workstation connected corporate network (either directly or through vpn) have user lock workstation , unlock using upn name. example:  bob@contoso.com
3. users workstation connected corporate network (either directly or through vpn) have user open command prompt , attempt launch application using runas.exe using users upn.    example:  runas /user bob@contoso.com "cmd /c echo account updated!"


ketan thakkar | microsoft online community support


Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group