Sep 03 2024 02:12 PM - edited Sep 03 2024 02:14 PM
I am attempting to install the Active Directory Federation Services role on a Server 2019 VM.
The initial configuration wizard fails when installing ADFS (GUI OR PowerShell - same outcome).
All checks pass, but the ADFS service takes roughly 75 seconds to start, so the wizard times out failed.
The database is built, the service account and certificate are verified, and the service is ACTUALLY STARTED.
Once it fails with "timeout" error, it never builds the APP Pool objects in IIS, and it never builds the objects to populate the AD FS MMC.
I have verified that the certificate is built correctly per multiple articles.
I followed https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/manually-configure-a-serv... to set up the GMSA service account
I have followed the guidance at https://learn.microsoft.com/en-us/troubleshoot/windows-server/system-management-components/service-n... to add time for the service to start, but the wizard appears to have its own timeout.
I have installed SQL Service Management Studio 20, and used it verify that the WID database and the permissions/roles for the service account match guidance.
I have verified the SPN and the permissions for the AD FS GUID for the farm.
Is there a way to complete the configuration with the long service start?
Sep 04 2024 01:53 AM
Sep 12 2024 08:12 AM
Solution@kyazaferr Thank you for your suggestions.
The problem was caused by Trellix blocking IPV6 for organizational reasons. That has been corrected, and the service is now starting quickly, as expected. The installation was able to finish, and we are moving on to the next stage.
Sep 12 2024 08:12 AM
Solution@kyazaferr Thank you for your suggestions.
The problem was caused by Trellix blocking IPV6 for organizational reasons. That has been corrected, and the service is now starting quickly, as expected. The installation was able to finish, and we are moving on to the next stage.