{"id":3942,"date":"2018-02-21T16:31:30","date_gmt":"2018-02-21T16:31:30","guid":{"rendered":"https:\/\/geekdecoder.com\/?p=3942"},"modified":"2018-02-21T16:31:30","modified_gmt":"2018-02-21T16:31:30","slug":"set-active-directory-federation-services","status":"publish","type":"post","link":"https:\/\/www.qbytes.cloud\/index.php\/2018\/02\/21\/set-active-directory-federation-services\/","title":{"rendered":"Install and Configure Active Directory Federation Services Windows 2016"},"content":{"rendered":"<p>This article is about how to Install and Configure Active Directory Federation Services Windows 2016.<\/p>\n<p>Now that we have Active Directory Install, we need to install ADFS so that we can login to the AWS console.<\/p>\n<p>Go to server manager and add roles and features.<br \/>\n<a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3943\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr1.png\" alt=\"\" width=\"950\" height=\"347\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr1.png 950w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr1-300x110.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr1-768x281.png 768w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\" \/><\/a><\/p>\n<p><!--more--><\/p>\n<p>Click Next<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3944\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr2.png\" alt=\"\" width=\"785\" height=\"561\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr2.png 785w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr2-300x214.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr2-768x549.png 768w\" sizes=\"auto, (max-width: 785px) 100vw, 785px\" \/><\/a><\/p>\n<p>Select Role Based<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3945\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr3.png\" alt=\"\" width=\"787\" height=\"562\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr3.png 787w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr3-300x214.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr3-768x548.png 768w\" sizes=\"auto, (max-width: 787px) 100vw, 787px\" \/><\/a><\/p>\n<p>Select the Server and Next<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3946\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr4.png\" alt=\"\" width=\"788\" height=\"563\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr4.png 788w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr4-300x214.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr4-768x549.png 768w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/a><\/p>\n<p>Select Active Directory Federation Services<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3947\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr5.png\" alt=\"\" width=\"783\" height=\"560\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr5.png 783w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr5-300x215.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr5-768x549.png 768w\" sizes=\"auto, (max-width: 783px) 100vw, 783px\" \/><\/a><\/p>\n<p>Leave the default and select next<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3948\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr6.png\" alt=\"\" width=\"786\" height=\"560\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr6.png 786w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr6-300x214.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr6-768x547.png 768w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><\/a><\/p>\n<p>Select Next<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3949\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr7.png\" alt=\"\" width=\"786\" height=\"563\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr7.png 786w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr7-300x215.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr7-768x550.png 768w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><\/a><\/p>\n<p>Select Install<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3950\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr8.png\" alt=\"\" width=\"786\" height=\"562\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr8.png 786w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr8-300x215.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr8-768x549.png 768w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><\/a><\/p>\n<p>Once Installation is complete, Click Close. Now we can configure the service.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3951\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr9.png\" alt=\"\" width=\"787\" height=\"563\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr9.png 787w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr9-300x215.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr9-768x549.png 768w\" sizes=\"auto, (max-width: 787px) 100vw, 787px\" \/><\/a><\/p>\n<p>The ADFS service will need a certificate. Follow the steps below to configure the SSL certificate.<\/p>\n<p>&nbsp;<\/p>\n<p>Click Start and then type &#8220;run&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4010\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc1.png\" alt=\"\" width=\"406\" height=\"143\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc1.png 406w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc1-300x106.png 300w\" sizes=\"auto, (max-width: 406px) 100vw, 406px\" \/><\/a><\/p>\n<p>In the console, select &#8220;File&#8221; &gt; &#8220;Add\/Remove Snap-in&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-4011\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2-1024x479.png\" alt=\"\" width=\"648\" height=\"303\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2-1024x479.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2-300x140.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2-768x359.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc2.png 1046w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Select &#8220;Certificates&#8221; &gt; &#8220;Add&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4012\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc3.png\" alt=\"\" width=\"669\" height=\"471\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc3.png 669w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc3-300x211.png 300w\" sizes=\"auto, (max-width: 669px) 100vw, 669px\" \/><\/a><\/p>\n<p>Select &#8220;Computer Account&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4013\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc4.png\" alt=\"\" width=\"509\" height=\"376\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc4.png 509w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc4-300x222.png 300w\" sizes=\"auto, (max-width: 509px) 100vw, 509px\" \/><\/a><\/p>\n<p>Select &#8220;Local Computer&#8221;. Then &#8220;Finish&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4014\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc5.png\" alt=\"\" width=\"507\" height=\"382\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc5.png 507w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc5-300x226.png 300w\" sizes=\"auto, (max-width: 507px) 100vw, 507px\" \/><\/a><\/p>\n<p>Click Finish.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4015\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc7.png\" alt=\"\" width=\"663\" height=\"465\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc7.png 663w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc7-300x210.png 300w\" sizes=\"auto, (max-width: 663px) 100vw, 663px\" \/><\/a><\/p>\n<p>On the following screen, right click on &#8220;Personal&#8221;, go to &#8220;View&#8221; and then click on &#8220;Options&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4016 size-large\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8-1024x317.png\" alt=\"\" width=\"648\" height=\"201\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8-1024x317.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8-300x93.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8-768x238.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc8.png 1424w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Select &#8220;Certificate Purpose&#8221; and then &#8220;OK&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4018\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc9.png\" alt=\"\" width=\"409\" height=\"319\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc9.png 409w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc9-300x234.png 300w\" sizes=\"auto, (max-width: 409px) 100vw, 409px\" \/><\/a><\/p>\n<p>Right Click on &#8220;Server Authentication&#8221;. Go to All Tasks and click on &#8220;Request New Certificate&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-4019\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10-1024x493.png\" alt=\"\" width=\"648\" height=\"312\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10-1024x493.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10-300x145.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10-768x370.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc10.png 1098w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Click Next.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4021\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc11.png\" alt=\"\" width=\"618\" height=\"457\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc11.png 618w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc11-300x222.png 300w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/><\/a><\/p>\n<p>Click Next.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4022\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc12.png\" alt=\"\" width=\"619\" height=\"453\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc12.png 619w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc12-300x220.png 300w\" sizes=\"auto, (max-width: 619px) 100vw, 619px\" \/><\/a><\/p>\n<p>Select the ADFS SSL Certificate. If you have not created this, please see this KB on how too install it.<\/p>\n<h5 class=\"entry-title \"><a href=\"https:\/\/qbytes.cloud\/installing-enterprise-ca-active-directory-federation-services\/\">Installing Enterprise CA for Active Directory Federation Services<\/a><\/h5>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc13.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4023\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc13.png\" alt=\"\" width=\"620\" height=\"455\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc13.png 620w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc13-300x220.png 300w\" sizes=\"auto, (max-width: 620px) 100vw, 620px\" \/><\/a><\/p>\n<p>Success page. Click Finish.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc14.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4024\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc14.png\" alt=\"\" width=\"621\" height=\"453\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc14.png 621w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc14-300x219.png 300w\" sizes=\"auto, (max-width: 621px) 100vw, 621px\" \/><\/a><\/p>\n<p>Now Close MMC. Choose &#8220;No&#8221; and close.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-4026\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15-1024x547.png\" alt=\"\" width=\"648\" height=\"346\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15-1024x547.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15-300x160.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15-768x410.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc15.png 1102w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Now, back at the server manager, click the top yellow warning icon at the top of server manager and click on &#8220;Configure the federation service on this server&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-3952\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10-1024x370.png\" alt=\"\" width=\"648\" height=\"234\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10-1024x370.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10-300x108.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10-768x278.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr10.png 1184w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Select &#8220;Create the first federation server in a federation server farm&#8221; as we are adding the first one.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3955\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr11.png\" alt=\"\" width=\"763\" height=\"563\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr11.png 763w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/addr11-300x221.png 300w\" sizes=\"auto, (max-width: 763px) 100vw, 763px\" \/><\/a><\/p>\n<p>Select the account and click next.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc16.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4027\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc16.png\" alt=\"\" width=\"752\" height=\"552\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc16.png 752w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc16-300x220.png 300w\" sizes=\"auto, (max-width: 752px) 100vw, 752px\" \/><\/a><\/p>\n<p>Select the SSL Certificate from the drop down and give the Federation Service a Display Name that the users will see at the login.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc17.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4028\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc17.png\" alt=\"\" width=\"751\" height=\"552\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc17.png 751w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc17-300x221.png 300w\" sizes=\"auto, (max-width: 751px) 100vw, 751px\" \/><\/a><\/p>\n<p>On the next page we are informed that we need to run a powershell command to add a Root Key. Windows manages the account and password for the service account.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc18.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4030\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc18.png\" alt=\"\" width=\"957\" height=\"553\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc18.png 957w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc18-300x173.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc18-768x444.png 768w\" sizes=\"auto, (max-width: 957px) 100vw, 957px\" \/><\/a><\/p>\n<p>To run the command, click on the top of the server manager page to display (do not close the ADFS wizard as we will need to come back to it).<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-4031\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19-1024x612.png\" alt=\"\" width=\"648\" height=\"387\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19-1024x612.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19-300x179.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19-768x459.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc19.png 1259w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Select All Servers on the left and then right click on the Domain Controller and then click on Windows PowerShell.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-4032\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20-1024x446.png\" alt=\"\" width=\"648\" height=\"282\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20-1024x446.png 1024w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20-300x131.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20-768x335.png 768w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc20.png 1188w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/a><\/p>\n<p>Run the command:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">Add-KdsRootKey -EffectiveTime (Get-Date).AddHours(-10)\n\n<\/pre>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc21.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4033\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc21.png\" alt=\"\" width=\"857\" height=\"229\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc21.png 857w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc21-300x80.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc21-768x205.png 768w\" sizes=\"auto, (max-width: 857px) 100vw, 857px\" \/><\/a><\/p>\n<p>Exit PowerShell. Now bring up the\u00a0ADFS wizard again. Click Previous.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc22.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4035\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc22.png\" alt=\"\" width=\"752\" height=\"552\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc22.png 752w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc22-300x220.png 300w\" sizes=\"auto, (max-width: 752px) 100vw, 752px\" \/><\/a><\/p>\n<p>Now click Next.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc23.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4036\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc23.png\" alt=\"\" width=\"753\" height=\"556\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc23.png 753w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc23-300x222.png 300w\" sizes=\"auto, (max-width: 753px) 100vw, 753px\" \/><\/a><\/p>\n<p>Now the warning is gone and we can set up the Group Managed service Account as &#8220;FsGmsa (Federation Service, Group Managed Service Account)&#8221;.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc24.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4037\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc24.png\" alt=\"\" width=\"747\" height=\"554\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc24.png 747w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc24-300x222.png 300w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\" \/><\/a><\/p>\n<p>Now, we need a databse to store the configuration data. In this case, I am creating an internal database.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc25.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4038\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc25.png\" alt=\"\" width=\"753\" height=\"555\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc25.png 753w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc25-300x221.png 300w\" sizes=\"auto, (max-width: 753px) 100vw, 753px\" \/><\/a><\/p>\n<p>Review Options.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc26.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4039\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc26.png\" alt=\"\" width=\"749\" height=\"551\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc26.png 749w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc26-300x221.png 300w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\" \/><\/a><\/p>\n<p>Next is the check. Click Configure.<\/p>\n<p>**Please note the warning that the root key<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc27.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4040\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc27.png\" alt=\"\" width=\"752\" height=\"556\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc27.png 752w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc27-300x222.png 300w\" sizes=\"auto, (max-width: 752px) 100vw, 752px\" \/><\/a><\/p>\n<p>Completion and errors.<\/p>\n<p><a href=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc28.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4041\" src=\"https:\/\/qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc28.png\" alt=\"\" width=\"1023\" height=\"688\" srcset=\"https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc28.png 1023w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc28-300x202.png 300w, https:\/\/www.qbytes.cloud\/wp-content\/uploads\/2018\/02\/mmc28-768x517.png 768w\" sizes=\"auto, (max-width: 1023px) 100vw, 1023px\" \/><\/a><\/p>\n<p>SPN<\/p>\n<p>It turns out this is a known issue that can be fixed by running the following at the command line. (Make sure you run the command window as an administrator.)<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\nsetspn -a host\/localhost adfssvc\n\n<\/pre>\n<p>Note that is the name of the service account I used.<\/p>\n<p>If the command is successful, you see output like this:<\/p>\n<p>Registering ServicePrincipalNames for<br \/>\nCN=ADFSSVC,CN=Users,DC=mydomain,DC=aws,DC=amazon,DC=com<br \/>\nhost\/localhost<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article is about how to Install and Configure Active Directory Federation Services Windows 2016. Now that we have Active Directory Install, we need to install ADFS so that we can login to the AWS console. Go to server manager and add roles and features.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[127],"tags":[],"class_list":["post-3942","post","type-post","status-publish","format-standard","hentry","category-winserv"],"_links":{"self":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts\/3942","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/comments?post=3942"}],"version-history":[{"count":0,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/posts\/3942\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/media?parent=3942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/categories?post=3942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.qbytes.cloud\/index.php\/wp-json\/wp\/v2\/tags?post=3942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}