locked
Unable to map service account identity RRS feed

  • Question

  • I'm building a basic ADFS test lab.  I now have three VM servers in my main domain - a DC, an STS and an APP server. 

    I initially installed ADFS 2.0 on the STS server using the Standalone federation server option.  I installed the basic ClaimsAwareWebAppWithManagedSTS app on the APP server.

    When trying to test it I kept getting System.Security.Principal.IdentityNotMappedException being thrown by the STS despite apparently having successfully authenticated on the adfs/ls login form using a domain account.

    So, I uninstalled ADFS from the STS server and reinstalled using the New Federation Server farm option.  At the Specify Service Account stage I chose my 'mydomain\adfssrvc' service account - previously created in ADDS and added to the Administrators group.  The account was recognized correctly in the Select User | Check Names dialogue.

    When I press OK I get an ADFS configuration wizard error dialog saying "The service account's identity could not be mapped.  Try using another account"

    I guess there's something wrong with my domain setup as the STS doesn't seem to recognize valid domain accounts but I don't know where to start.

    Can anyone help?

    Tuesday, March 23, 2010 5:09 PM

Answers

  • I bet you cloned all your lab machines from the same VM image (clone). Have your DC and your APP server come from different clones so they don't have SID conflicts.
    • Marked as answer by jks Monday, June 7, 2010 9:10 PM
    Monday, June 7, 2010 8:50 PM

All replies

  • I bet you cloned all your lab machines from the same VM image (clone). Have your DC and your APP server come from different clones so they don't have SID conflicts.
    • Marked as answer by jks Monday, June 7, 2010 9:10 PM
    Monday, June 7, 2010 8:50 PM
  • Dead right - I found a post somewhere else that hinted that might be the problem so I reinstalled the OS on all the VMs and it worked fine. Sorry - I should have posted my own solution!
    Monday, June 7, 2010 9:09 PM