Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > ADFS - web server error

Reply
Fix Vista Errors
Thread Tools Display Modes

ADFS - web server error

 
 
Avis
Guest
Posts: n/a

 
      11-19-2009




I am trying to configure an NT-token based app. The configuration seems to be
fine when checked with the ADFS diagnostics tool on the web server. I do not
have access to the Account FS or the Resource FS as they are hosted elsewhere
but they seem to be working fine as I am able to successfully login. After
logging in I get access denied to my application and the following errors
show up in the event logs.

Application log: ADFS ISAPI Extension error

The ADFS Web Agent Internet Server Application Programming Interface (ISAPI)
Extension was unable to obtain a Windows NT token from the authentication
service.

An anonymous token will be generated for this request.


Security log:

Error 1:

The user has not been granted the requested
logon type at this machine

Logon Type: 3

Error 2: ADFS Web Agent Authentication Service Auditor

The client presented a valid XML token, but an error occurred during the
attempt to generate a Windows NT token from the security IDs (SIDs). The
error code was 1385.


I have created shadow accounts and we are using UPN claims. I have added the
necessary UPN suffixes in the AD of which the web server is a member.

What am I missing?

Let me know if I need to provide more information.

Regards,
Avis

 
Reply With Quote
 
Joe Kaplan
Guest
Posts: n/a

 
      11-20-2009
1385 = "the user has not been granted the required logon type on this
computer". That usually means that something in the local security policy
has changed the policy in regards to the logon type which in this case is
"3" which means network login.

Check in secpol.msc to see if someone has removed the "authenticated users"
group from the "access this computer from the network" security policy.

There may also be something else weird going on with the login but I'd start
there to see if that might help.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
"Avis" <> wrote in message
news:8B1FD9B3-1499-42E2-9F5F-...
>I am trying to configure an NT-token based app. The configuration seems to
>be
> fine when checked with the ADFS diagnostics tool on the web server. I do
> not
> have access to the Account FS or the Resource FS as they are hosted
> elsewhere
> but they seem to be working fine as I am able to successfully login. After
> logging in I get access denied to my application and the following errors
> show up in the event logs.
>
> Application log: ADFS ISAPI Extension error
>
> The ADFS Web Agent Internet Server Application Programming Interface
> (ISAPI)
> Extension was unable to obtain a Windows NT token from the authentication
> service.
>
> An anonymous token will be generated for this request.
>
>
> Security log:
>
> Error 1:
>
> The user has not been granted the requested
> logon type at this machine
>
> Logon Type: 3
>
> Error 2: ADFS Web Agent Authentication Service Auditor
>
> The client presented a valid XML token, but an error occurred during the
> attempt to generate a Windows NT token from the security IDs (SIDs). The
> error code was 1385.
>
>
> I have created shadow accounts and we are using UPN claims. I have added
> the
> necessary UPN suffixes in the AD of which the web server is a member.
>
> What am I missing?
>
> Let me know if I need to provide more information.
>
> Regards,
> Avis
>


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Error downloading messages after upgrade to WLM 12. Patricio Windows Live Mail 9 11-17-2009 06:33 PM
Error not able to loging after upgrading domain controller Alexyy Active Directory 6 11-10-2009 07:09 AM
Re: cannot syn with Windows Mobile 5.0 Chris De Herrera ActiveSync 4 09-29-2006 04:05 AM
Unresolved items: incredible! Massimo ActiveSync 9 04-18-2006 04:11 PM
ActiveSync 4.1, Calendar and "Processing" Dale Reeck ActiveSync 10 12-20-2005 01:44 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59