AD FS Help Troubleshooting

Troubleshooting Guides

AD FS Help provides easy walkthrough troubleshooting guides for resolving AD FS issues . Choose the symptom that closely matches your scenario, and then follow the steps in the workflow for fast issue resolution.

Mitigating Password Spray Attacks and Account Lockouts

This workflow helps mitigate and prevent future password spray attacks, determine the cause of account lockouts, and set up lockout protection. Use this workflow if you want to set up Extranet Lockout, find the cause of a password spray attack, or find the cause of an account lockout.

Start troubleshooting

Congestion Control

This workflow assists with troubleshooting AD FS load or congestion issues.

Start troubleshooting

Error accessing application federated with AD FS

This workflow helps to resolve sign-in issues for applications federated with Active Directory Federation Services (AD FS). Use this workflow if users are getting an error in an application federated with AD FS.

Start troubleshooting

Managing and troubleshooting AD FS certificates

This workflow helps to provide guidance on how to deploy new certificates as well as troubleshoot problems with existing certificates. It covers both Active Directory Federation Service (AD FS) and Web Application Proxy (WAP) servers.

Start troubleshooting

Users can't sign-in with alternate ID

This workflow helps to resolve sign-in/configuring issues with alternate ID.

Start troubleshooting

All users can't login using AD FS from an external network

This workflow helps to resolve sign-in issues with Active Directory Federation Services (AD FS) from an external network. Use this workflow if users are not able to authenticate using AD FS from outside corpnet. This would usually include authentications occuring via the Web Application Proxy (WAP).

Start troubleshooting

All users can't login using AD FS from inside corpnet

This workflow resolves sign-in issues with Active Directory Federation Services (AD FS) inside corpnet. It does not cover seamless SSO / unexpected prompt configuration or troubleshooting of sign-in happening via the Web Application Proxy (WAP).

Start troubleshooting

SSO does not work and users are getting prompted for credentials

This workflow resolves Integrated Windows Authentication SSO issues. If users are seeing unexpected NTLM or forms based authentication prompts, use this workflow to troubleshoot such issues.

Start troubleshooting

Proxy trust between Web Application Proxy (WAP) and Active Directory Federation Service (AD FS) server is broken

This workflow helps to resolve issues with proxy trust configuration with AD FS. Use this workflow if you are seeing problems with your Web Application Proxy (WAP) trust configuration.

Start troubleshooting

Connect Health for AD FS data freshness alert troubleshooting steps

Azure AD Connect Health for AD FS Data Freshness Alert - Health service data is not up-to-date troubleshooting steps.

Start troubleshooting