{"id":1751,"date":"2015-03-27T14:42:49","date_gmt":"2015-03-27T13:42:49","guid":{"rendered":"https:\/\/sccmfaq.wordpress.com\/?p=1751"},"modified":"2015-03-27T14:42:49","modified_gmt":"2015-03-27T13:42:49","slug":"microsoft-ems-intune-adfs-federation-relying-party-trust-secure-hash-algorithm","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=1751","title":{"rendered":"Microsoft EMS &#8211; Intune &#8211; ADFS federation relying party trust secure hash algorithm"},"content":{"rendered":"<p>Hi, here&#8217;s Martin again with a\u00a0short blogpost about the ADFS federation for Intune.<\/p>\n<p>I was going through the Options of the ADFS Infrastructure after reading this very interesting Blog on TechNet from David Gregory:<br \/>\nhttp:\/\/blogs.technet.com\/b\/askpfeplat\/archive\/2015\/03\/02\/adfs-deep-dive-onboarding-applications.aspx<\/p>\n<p>There\u00a0is the Secure Hash algorithm Pointed out:<\/p>\n<blockquote><p>The relying party trust in ADFS must be configured with the correct secure hash algorithm. Most SAML applications will support SHA-1 while most WS-Fed applications will support SHA-256.<\/p><\/blockquote>\n<p><!--more--><\/p>\n<p>Well then, I was going on to my ADFS Farm (actually it isn&#8217;t a farm, only one Server \ud83d\ude42 ), and changed the secure hash algorithm to SHA-256 on the &#8220;Microsoft Office 365 Identity Platform&#8221; relying Party trust and changed the secure hash algorithm:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2015\/03\/securehashalgo01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1753\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2015\/03\/securehashalgo01.png?w=300\" alt=\"Change Secure Hash Algorithm\" width=\"300\" height=\"228\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/securehashalgo01.png 871w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/securehashalgo01-300x228.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/securehashalgo01-768x583.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAfterwards I was still able to Login to Office365 Service, and also some other ADFS related Services, except the Intune Service (on normal Browser and on the mobile Devices). I always ended up with a short, not much saying error message on a mostly Grey Webpage, which was telling me:<br \/>\nAn unexpected error has occurred.<br \/>\nAn error occurred while processing your request.<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2015\/03\/intune_error.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1755\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2015\/03\/intune_error.png?w=300\" alt=\"Unexpected Error\" width=\"300\" height=\"99\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/intune_error.png 1061w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/intune_error-300x99.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/intune_error-1024x337.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2015\/03\/intune_error-768x253.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><strong>After changing back the secure hash algorithm to SHA-1<\/strong>, everthing works fine. Unfortunately I can&#8217;t find official Information about this Topic, but I will leave an eye on this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi, here&#8217;s Martin again with a\u00a0short blogpost about the ADFS federation for Intune. I was going through the Options of the ADFS Infrastructure after reading this very interesting Blog on TechNet from David Gregory: http:\/\/blogs.technet.com\/b\/askpfeplat\/archive\/2015\/03\/02\/adfs-deep-dive-onboarding-applications.aspx There\u00a0is the Secure Hash algorithm Pointed out: The relying party trust in ADFS must be configured with the correct secure [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,10,24],"tags":[],"class_list":["post-1751","post","type-post","status-publish","format-standard","hentry","category-adfs","category-byod","category-mdm"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1751","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1751"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1751\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1751"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}