{"id":2234,"date":"2016-04-23T11:12:55","date_gmt":"2016-04-23T09:12:55","guid":{"rendered":"http:\/\/blog.hosebei.ch\/?p=2234"},"modified":"2016-04-23T11:12:55","modified_gmt":"2016-04-23T09:12:55","slug":"adfs-install-web-application-proxy-fails-with-401-unauthorized","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=2234","title":{"rendered":"ADFS &#8211; Install Web Application Proxy fails with 401: Unauthorized"},"content":{"rendered":"<p>Hi,<\/p>\n<p>today I faced the issue, that when I tried to install my Web Application Proxy for ADFS, it permanently fails with the Event ID 422:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall01.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall01.png?w=300\" alt=\"AD FS Event ID 422\" width=\"300\" height=\"259\" class=\"aligncenter size-medium wp-image-2235\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall01.png 702w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall01-300x259.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nWith Text:<br \/>\n\u200eUnable to retrieve proxy configuration data from the Federation Service.<br \/>\nAdditional Data<br \/>\nTrust Certificate Thumbprint:<br \/>\n3CD8F7C4697ED510546F74C25B4FD4F8C183CE34 <\/p>\n<p>Status Code:<br \/>\nUnauthorized<br \/>\nException details:<br \/>\nSystem.Net.WebException: The remote server returned an error: (401) Unauthorized.<br \/>\n   at System.Net.HttpWebRequest.GetResponse()<br \/>\n   at Microsoft.IdentityServer.Management.Proxy.StsConfigurationProvider.GetStsProxyConfiguration()<br \/>\n&#8212;- End Snip&#8212;<br \/>\nI was quite sure, that I had everything quite well configured, and that I was using the correct certificate.<!--more--><\/p>\n<p>With the Error (401) Unauthorized, I thought it might be an issue with the account required to connect to the ADFS Farm, but this wasn&#8217;t the case. I found this <a href=\"https:\/\/blogs.technet.microsoft.com\/rmilne\/2015\/04\/20\/adfs-2012-r2-web-application-proxy-re-establish-proxy-trust\/\" target=\"_blank\">Blog<\/a> that tells to check and Enable Device Registration Service in some circumstances, but I had this feature already activated.<br \/>\nSo, time to shine, because I had this Installation already up and running, and was wondering why I could not create the Trust between the Web Application Proxy and the AD FS Farm.<br \/>\nI then checked the ADFS Service properties and recognized, that there was an http address used:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall02.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall02.png?w=268\" alt=\"Fedration Service Identifier HTTP\" width=\"268\" height=\"300\" class=\"aligncenter size-medium wp-image-2237\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall02.png 414w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2016\/04\/adfs_wapinstall02-268x300.png 268w\" sizes=\"auto, (max-width: 268px) 100vw, 268px\" \/><\/a><br \/>\nSo port 80 would be required to open to the Farm from the Proxy Servers.<br \/>\nAfter I have added this rule to the Firewall, the WAP could be federated easily and worked afterwards as expected. I still wonder why this worked before, or if I have changed something on the Firewall in advance of this issue.<\/p>\n<p>Hope this helps someone else<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hi, today I faced the issue, that when I tried to install my Web Application Proxy for ADFS, it permanently fails with the Event ID 422: With Text: \u200eUnable to retrieve proxy configuration data from the Federation Service. Additional Data Trust Certificate Thumbprint: 3CD8F7C4697ED510546F74C25B4FD4F8C183CE34 Status Code: Unauthorized Exception details: System.Net.WebException: The remote server returned an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,3,7,17],"tags":[],"class_list":["post-2234","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-adfs","category-azure-ad","category-emm"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2234"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2234\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}