ADFS - Not Authorized To View Message



I'm getting SO close to making this work I can't stand it.

I've gotten ADFS implemented to the point that I go to http://servername/certsrv
and am prompted to accept two separate certificates, then a logon box
appears. I type in my AD user name and password and Internet Explorer
starts doing something, the word "Working..." appears in the title
bar, then I get a page that says "You are not authorized to view this
page".

In the ifsaplog have a failures. One in particular says
webssophandleupnlogon failed for urn:federation:domain:domain\upn.
It's not even possible to logon with domain/UPN is it?

I think I may have set up my URI wrong? Or my claims? I'm using a
group claim and I mapped it an AD group. Am I supposed to use an
identity claim?

In my event logs on the web server there is an event 104 every time I
get the IE error page. Part of the message says "The cookies that
were presented by the client could not be validated.


There is a light at the end of the tunnel finally, hopefully it's not
a train.

Thanks for any help you can provide!

.



Relevant Pages

  • RE: Account Lockout (Event ID: 539) Alert message
    ... >Subject: Account Lockout Alert message ... >SBS box with a subject just like the subject of this post. ... > For more information about this event, see the event logs on the server ... >Logon Failure: ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA fails for all non-administators
    ... Certain users cannot log into the OWA system .. ... The event logs show this ... The server was unable to logon the Windows NT account 'joachim.reitman' due ... You may want to reapply the security settings. ...
    (microsoft.public.exchange2000.clients)
  • Security Log: Event ID 537 issue
    ... I support a SBS2003 Standard network at my wife's office and it has been ... An error occurred during logon ... of them) were turned on these errors starting appearing in the Event Logs ... than fifty times for these 2 Tablets. ...
    (microsoft.public.windows.server.sbs)
  • Re: RWW Monitoring
    ... logoff June VSXP Tue 22/02/2005 10:41:08.45 ... logon MickM VSXP Tue 22/02/2005 10:42:01.07 ... > network the openess of RWW, and the potential breach that> could ensue, You would think that someone or Microsoft would have set up a> more complete reporting - monitoring tool. ... If you users use RWW to logon to network, there will be>> following event in the event logs. ...
    (microsoft.public.windows.server.sbs)