Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to troubleshoot AD FS - DNS

Download for Free
Free, fully functional 30-day trial

Active Directory Federation Services (ADFS) is Microsoft's federated identity and access management solution that provides single sign-on (SSO) capability to web applications. The smooth functioning of ADFS has several dependencies such as the SQL server in which the configuration database is stored, DNS which resolves the federation service to appropriate IP address, certificates which form the core of ADFS, and so on. Even a minor issue in any of these can lead to problems in ADFS operations, and affect users' ability to access applications like Office365. For example, if a certificate expires and loses validity, it can collapse ADFS functionality.

DNS name resolution must be one of the first things to check while troubleshooting ADFS. DNS must be able to resolve the name of the federation service and point to the IP address of the ADFS server or the load balancer in your server farm. The following are some of the name resolution tests to be performed in case ADFS is not working or responding.

  • PING test
  • PING test sends Internet Control Message Protocol (ICMP) Echo Request messages to another TCP/IP computer to verify IP-level connectivity. To conduct the PING test:

    1. Open a command prompt.
    2. Type ping followed by domain name. Example: ping manageengine.com.
    3. Press Enter
    4. Reply from the server will be displayed.
    5. how-to-troubleshoot-adfs-dns
  • Name server lookup (NSLookup)
  • The NSLookup command line tool can be used to fetch diagnostic details on DNS infrastructure.

    1. Open a command prompt.
    2. Type nslookup followed by domain name. Example: nslookup manageengine.com.
    3. Press Enter.
    4. Server DNS information will be displayed.
    5. how-to-troubleshoot-adfs-dns-1
  • Tracert
  • Tracert command line utility traces the path to a destination by by sending Internet Control Message Protocol (ICMP) Echo Request or ICMPv6 messages with increasing Time to Live (TTL) field values.

    1. Open a command prompt.
    2. Type tracert followed by domain name. Example: tracert manageengine.com
    3. The path traced to reach the destination server will be displayed.
    4. how-to-troubleshoot-adfs-dns-2

ADAudit Plus simplifies ADFS tracking by fetching all authentication attempts recorded by ADFS and generating predefined ADFS Auditing reports along with intuitive graphical representation of the same for easy comprehension. By auditing ADFS, ADAudit Plus keeps administrators informed about trends in user activity and helps organizations meet compliance requirements. It also provides users the option to generate custom reports and export them in a preferred format (PDF, XLS, HTML, and CSV).

Native auditing becoming a little too much?

Simplify Active Directory Federation Services auditing and reporting with ADAudit Plus.

Get Your Free Trial Fully functional 30-day trial

Request 1-on-1 demo

  •  
  •  
  •  
  •  
  •  
  • -Select-
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.

Thanks

One of our solution experts will get in touch with you shortly.

ADAudit Plus Trusted By