If you have session problems in ADFS, you may need to disable Local Security Authority (LSA) credential caching on the AD FS server temporarily. This can affect any application that uses claims based authentication including SharePoint, CRM, Office 365, etc. To do this, you need to:
Showing posts with label ADFS. Show all posts
Showing posts with label ADFS. Show all posts
Sunday, April 14, 2013
404 Error for Isolated Users in Dynamics CRM
I had an issue recently where one user was getting a 404 error when trying to log into CRM. While troubleshooting this issues I tried everything I could think of, including disabling Local Security Authority (LSA) credential caching on the ADFS server, recreating the user's Active Directory account, disabled/re-enabled her CRM account, purged her kerberos tickets, deleted her cookies, killed her ADFS sessions, rebooted servers, reset passwords, checked her security roles, etc. After trying every perceivable resolution, this is what I had to do to fix the issue.
Labels:
404,
Active Directory Federation Services,
ADFS,
credential caching,
LSA,
Microsoft Dynamics CRM 2011
Tuesday, March 19, 2013
Dynamics CRM: Authentication is Required - Timing Out and Prompting for Credentials
If you are running Dynamics CRM 4.0 and 2011 with claims based authentication, by default you get a prompt saying "Authentication is Required" after 20 minutes. If you want to extend this timeout, you need to make some changes to the relying party trust in Active Directory Federation Services (ADFS).
Labels:
Active Directory Federation Services,
ADFS,
ADFSRelyingPartyTrust,
Authentication is Required,
Microsoft Dynamics CRM 2011,
Microsoft Dynamics CRM 4.0,
powershell,
timeout,
TokenLifetime
Subscribe to:
Posts (Atom)