Windows 10: ADFS page blocking bypassed MFA for select users

Discus and support ADFS page blocking bypassed MFA for select users in Windows 10 Customization to solve the problem; Hi Microsoft Support, Good day! I need help on how to remove the ADFS page blocking my exempted user not to use MFA. The user or mailbox account is... Discussion in 'Windows 10 Customization' started by Maynard Lavalle, Oct 4, 2019.

  1. ADFS page blocking bypassed MFA for select users


    Hi Microsoft Support,

    Good day! I need help on how to remove the ADFS page blocking my exempted user not to use MFA. The user or mailbox account is already bypassed on the MFA application. Almost all users are using MFA to login to portal.office.com.

    Thank in advance!

    :)
     
    Maynard Lavalle, Oct 4, 2019
    #1
  2. vecon Win User

    Recommendation: Load balancer for ADFS environment?

    We want to put in ADFS for our current network to support about 30K authenticated users, currently to start off just for sharepoint application, but potentially will support other application/ users as well.

    Looking for recommendation on whether we should go with virtual or hardware based Load Balancer, and
    which vendor of LB that people tend to adopt for their ADFS and WAP servers? Imagine we'll need to get the LB that can support Layer 7

    Here is how we are currently spec'ed out so far:

    • 2 WAP servers (Win2016) sit behind a LB and all on DMZ
    • 2 ADFS servers (Win2016) sit behind another LB and all on Internal network
    • DC server is on Internal network as well

    ----

    Can anyone explain how the traffic/federation process goes (step by step) when user access the website from the internet (please include how request is being passed/redirect between webserver, WAP, ADFS, and DC servers)

    Thanks!
     
    vecon, Oct 4, 2019
    #2
  3. ADFS authentication loop on login page

    I deployed a HA ADFS environment with NLB.

    There are several URLs can access the ADFS service: https://hostname.domain.local, https://adfs.domain.local, https://nlb-adfs.domain.local.

    When I access the ADFS service URL: https://adfs.domain.local, I can authenticate users normally with a signed-in status, but if I try to access the other URLs, the user can't be accessed and will be redirected back to login page again and again.

    In the event viewer I can find even id 4672,4623,4634. It seems the user was logged off once it was logged on.

    The description of the event id 4634 is

    This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.

    How can I get through with it?

    Thank you!
     
    jameszeng1, Oct 4, 2019
    #3
  4. ADFS page blocking bypassed MFA for select users

    portal.office.com (Office 365) to ADFS then This page can’t be displayed on IE11

    I am using Office 365 with ADFS authentication.

    When I go to portal.office.com, and the following is true, I get a This page can’t be displayed error just as the browser tries to authenticate against my ADFS server:

    • Using IE or Edge in Windows 10 (IE version: 11.103.10586.0)
    • Computer joined to my domain
    • On the WAN whether or not I'm connected to the VPN
    It will work if:

    • I'm on my corporate LAN
    • There is no problem with Windows 8 in the above setup (IE 11.0.9600.12205)
    • If I use Firefox (probably chrome too, haven't bothered to test)

    Other notes:

    I can properly resolve the external address of my adfs server (otherwise Firefox wouldn't work)

    If i replace the server address (adfs.domain.com) with the WAN IP, it will authenticate

    My ADFS server along with *.microsoftonline.com and *.office.com is in my Local intranet zone.

    Enabling or disabling "Display intranet sites in Compatibility View" does not resolve the issue

    From what I can tell, IE cannot resolve the address of my adfs server or refuses to talk to it. I don't know how a browser would not be able to resolve an address because I don't believe it's the job of the browser to do name resolution/interpretation
    at any level.

    This affects all Windows 10 clients.

    Before asking me if I have checked TLS settings, etc in IE please remember: I am able to connect to my adfs server if I use the IP address in IE.

    Before asking if my DNS settings are setup properly: Firefox works fine without me entering the IP.

    I'm stuck and have no idea what to try next.
     
    Michael-Adam, Oct 4, 2019
    #4
Thema:

ADFS page blocking bypassed MFA for select users

Loading...
  1. ADFS page blocking bypassed MFA for select users - Similar Threads - ADFS page blocking

  2. ADFS Login Page Customisation Help

    in Windows 10 Gaming
    ADFS Login Page Customisation Help: Hi, I need some help with customising an existing ADFS login page. There is already a theme in place and the login description has been filled out. But I don't know what HTML was applied. Is there a way that I cant get what was used so that I could amend it. Thanks...
  3. ADFS Login Page Customisation Help

    in Windows 10 Software and Apps
    ADFS Login Page Customisation Help: Hi, I need some help with customising an existing ADFS login page. There is already a theme in place and the login description has been filled out. But I don't know what HTML was applied. Is there a way that I cant get what was used so that I could amend it. Thanks...
  4. ADFS Login Page Customisation Help

    in Windows 10 Installation and Upgrade
    ADFS Login Page Customisation Help: Hi, I need some help with customising an existing ADFS login page. There is already a theme in place and the login description has been filled out. But I don't know what HTML was applied. Is there a way that I cant get what was used so that I could amend it. Thanks...
  5. One user can't login to ADFS

    in Windows 10 Gaming
    One user can't login to ADFS: There's a user of our farm who's having problems to login to ADFS. He gets the ADFS login page but he cannot login. He constantly gets the page again and again. When he types a wrong password, he gets a message that the password is wrong. But once he uses correct credentials...
  6. One user can't login to ADFS

    in Windows 10 Software and Apps
    One user can't login to ADFS: There's a user of our farm who's having problems to login to ADFS. He gets the ADFS login page but he cannot login. He constantly gets the page again and again. When he types a wrong password, he gets a message that the password is wrong. But once he uses correct credentials...
  7. One user can't login to ADFS

    in AntiVirus, Firewalls and System Security
    One user can't login to ADFS: There's a user of our farm who's having problems to login to ADFS. He gets the ADFS login page but he cannot login. He constantly gets the page again and again. When he types a wrong password, he gets a message that the password is wrong. But once he uses correct credentials...
  8. MFA for privileged users for windows logon and RDP using Azure MFA

    in Windows 10 Software and Apps
    MFA for privileged users for windows logon and RDP using Azure MFA: Hi Reader, Is it possible to implement MFA during windows login and rdp session using azure MFA? If not, what is the best Microsoft product or third-party product to achieve the same?Thank you....
  9. VPN / Blocked bypass

    in Windows 10 Ask Insider
    VPN / Blocked bypass: So basically I bought GeForce now to play on my school pc which as you could imagine has restrictions. I play GeForce now via chrome browser because i cannot download it’s actual software because of the admin pop up to download it (when u download stuff and says install file...
  10. Bypassing Geo Blocking

    in Windows 10 Network and Sharing
    Bypassing Geo Blocking: What's up guys? So I'm living out here in Japan and a lot of my content is blocked from the US. Webpages I always go to, internet radio, apps on my phone, etc. Lot of stuff is geo blocked. I was looking for a way around these blocks. Ive installed many VPN apps on my phone...