Back

ADFS Token Signing Certificate Expiry Causes Sign-On Errors

When you install ADFS you must upload your certificate settings thumbprint to the Federated Relying Party in this case Office 365 The default exp...

2 min read
Published on Apr 8, 2012
ADFS Token Signing Certificate Expiry Causes Sign-On Errors

When you install ADFS, you must upload your certificate settings/thumbprint to the Federated Relying Party, in this case, Office 365.  The default expiration with standard ADFS 2.0 installation is a self signing certificate that expires every year.

Symptoms of user Errors in Browser on Office 365 Portal/Service Logon using federated identity:

  • “There was a problem accessing the site. Try to browse the site again.”
  • “Your organization could not sign you in to this service. There may be a system error. Please contact administrator at your organization if this problem persists.”

Application and Services Logs > ADFS 2.0 > Admin:

  • Event ID 358: Restarting Issuance ServiceHost. This restart is necessary because a change was detected in the certificates that this service host uses. Requests that are served by endpoints of this service host may fail during restart.

Potential Solution If these events occur, it’s a good bet your ADFS signing certificate expired and must be Ensure latest Microsoft Online Services Module for PowerShell installed. Download the module for your 32 or 64 bit system here.

Note - Microsoft Online Services Identity Federation Management PowerShell Module is deprecated and everything can now be configured in the Microsoft Online Services Module.

Powershell Commands:

  • Connect-MsolService Note - You will be prompted for credentials, enter a NON-Federated Office 365 admin account.

  • Optional, only If you’re NOT Running PowerShell From ADFS server: Set-MSOLAdfscontext -Computer YourAdfsServer.mydomain.local

  • Update-MSOLFederatedDomain -DomainName YourDomain.com

  • You can verify the thumbprint updated on Microsoft Online Federation gateway:Get-MSOLFederationProperty -DomainName YourDomain.com

Note – You will also need to update your other SAML Relying Parties such as Concur, Webex, Salesforce, Zendesk, and Google Apps.

If you would like assistance in federation for your organization, please learn more about AgileIdentity, our fixed price identity and access solution.

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

Common Questions About Azure Migration Answered

Common Questions About Azure Migration Answered

Get answers to the most common Azure migration questions. Learn about costs, best practices, security, compliance, and troubleshooting cloud migration challenges.

Apr 29, 2025
3 min read
AVD vs W365 in GCC high reducing your CMMC scope

AVD vs W365 in GCC High Reducing Your CMMC Scope and Simplifying Compliance

Comparing AVD vs W365 for GCC High? Learn how each can reduce your CMMC assessment scope and simplify security and compliance management in government environments.

Apr 28, 2025
7 min read
Office 365 License Comparison: Business Plans Vs. E5, E3 and E1

Implementing Cybersecurity Policies for CMMC Compliance and Managing CUI

CMMC compliance requires well-documented cybersecurity policies. Learn how to implement security controls, create an SSP and POA&M, and manage Controlled Unclassified Information (CUI).

Apr 25, 2025
7 min read
CMMC compliance for DoD contractors

CMMC Compliance Requirements for DoD Contractors and Subcontractors in the Defense Industry

CMMC compliance is mandatory for DoD contractors and subcontractors. Learn about certification levels, requirements, and the consequences of failing to meet compliance.

Apr 24, 2025
6 min read
How to prepare for a CMMC compliance audit

CMMC Compliance Audit Preparation: A Complete Checklist for Small Businesses

Preparing for a CMMC compliance audit is critical for DoD contractors. Use this checklist to perform a gap analysis, assess CMMC readiness, and prepare for a Level 2 assessment.

Apr 23, 2025
8 min read
FAR CUI vs CMMC Understanding

FAR CUI vs CMMC Understanding the Differences and Overlaps

FAR CUI and CMMC both focus on protecting sensitive federal data, but they have key differences. Learn how they work together and whether FAR CUI compliance aligns with CMMC.

Apr 15, 2025
10 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don't want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122

Secure. Defend. Thrive.

Don't want to wait for us to get back to you?

Discover more about Agile IT's range of services by reaching out

Schedule a Free Consultation