Part 3 – Lab Phase 1: Domain Controller, CA & First ADFS Server

Part 3 – Lab: ADFS Installation & Configuration (2016)
Part 3 – Lab

ADFS Installation & Configuration (2016)

Prerequisites, CA Template, DNS, and Full ADFS Server Setup

1. Objective & Lab Context

In this hands-on lab we will install and configure a new ADFS 2016 federation server and join it to an existing domain. The environment already contains:

  • Domain Controller + Enterprise CA – Windows Server 2025 (pdc.maharjan.np)
  • Exchange Server SE – Windows Server 2025 (mail.mhr.com.np) – will be used later as a relying party

We’ll prepare the prerequisites, issue the required SSL certificate, and then deploy the ADFS role. By the end, you’ll have a fully functional ADFS endpoint ready for federation with Exchange and other applications.

2. Assumptions – Existing Infrastructure

We assume the following servers are already deployed and configured:

ServerRoleHostname / FQDNIP
PDCDomain Controller + Enterprise CApdc.maharjan.np10.10.10.94
EXCHExchange Server SEmail.mhr.com.np10.10.10.95

Below are overview screenshots of the three main server management consoles (Domain Controller, Certificate Authority, and Exchange Server) to confirm the environment is ready.

Server Manager – Domain Controller (PDC)
Server Manager – Domain Controller (PDC)
🖱️ Click image to view full size
Server Manager – Microsoft Exchange Server SE
Microsoft Exchange Server SE
🖱️ Click image to view full size
Server Manager – Active Directory Federation Service (ADFS)
ADFS
🖱️ Click image to view full size

3. Full Prerequisites & Administrative Privileges

Before installing ADFS, ensure the following are in place.

3.1 Administrative Rights

  • You must be a member of Domain Admins or Enterprise Admins to deploy the ADFS role and create the farm.
  • For Exchange integration later, you’ll need Organization Management role group membership.
Active Directory Users and Computers – Admin Privilege for ADFS-Admin User
ADFS-Admin user properties
🖱️ Click image to view full size
Active Directory Users and Computers – Admin Privilege for ADFS-Admin User (continued)
ADFS-Admin group membership
🖱️ Click image to view full size

3.2 Group Managed Service Account (gMSA)

ADFS services should run under a gMSA for security and simplified password management. We created it on the DC:

PowerShell – gMSA creation – adfsGMSA
PowerShell gMSA creation
🖱️ Click image to view full size
PowerShell – Service Account Verify
Service Account Verify
🖱️ Click image to view full size

3.3 Network & Firewall

  • Port 443 (HTTPS) must be open between clients, ADFS, and Exchange.
  • Port 80 (HTTP) is required for CRL distribution from the CA (pdc.maharjan.np).
  • All servers must be on the same private network (or have proper routing).

3.4 Internal DNS Records

Create the following A-records on the internal DNS server (PDC):

  • adfs.mhr.com.np → IP of ADFS server (10.10.10.93)
  • certauth.adfs.mhr.com.np → IP of ADFS server (for certificate enrollment)
  • mail.mhr.com.np → IP of Exchange server (already exists)
DNS Manager – A-records created for ADFS
A-records created for ADFS
🖱️ Click image to view full size
DNS Manager – A-records created for ADFS CertAuth
A-records created for ADFS CertAuth
🖱️ Click image to view full size

4. Step 3 – Create Web Server Certificate Template on CA

ADFS will need an SSL certificate with Subject Alternative Names. We’ll duplicate the built-in Web Server template to allow SANs and exportable private keys.

  1. Log in to the CA server (pdc.maharjan.np) and open Certificate Templates console (certtmpl.msc).
  2. Right‑click Web Server and select Duplicate Template.
  3. On the General tab, give it a new name (e.g., ADFS Web Server) and set validity period as needed.
  4. On the Subject Name tab, ensure Supply in the request is selected so we can add SANs.
  5. On the Request Handling tab, check Allow export of private key.
  6. Complete the wizard and Add the new template to the CA (right‑click Certificate TemplatesNewCertificate Template to Issue).
Certificate Templates Console – Duplicate Template
Certificate Templates Duplicate
🖱️ Click image to view full size
Template Properties – Subject Name tab
Template Properties Subject Name
🖱️ Click image to view full size
Template Properties – Request Handling – Allow export
Template Properties Allow export
🖱️ Click image to view full size
Template Properties – Security – Allow Enroll
Template Properties Allow Enroll
🖱️ Click image to view full size
CA – Issued Templates list showing new template
CA Issued Templates
🖱️ Click image to view full size
CA – Issued Templates – ADFS SSL
ADFS SSL
🖱️ Click image to view full size

4.1 Request SSL Certificate for ADFS

On the ADFS server (before installing the role), request a certificate using the new template:

  1. Open certlm.msc (Local Machine certificates).
  2. Right‑click PersonalAll TasksRequest New Certificate.
  3. Select the enrollment policy that points to your CA.
  4. Choose the ADFS Web Server template.
  5. Configure:
    • Subject Name (CN): adfs.mhr.com.np
    • Subject Alternative Names (DNS): adfs-01.maharjan.np, certauth.adfs.mhr.com.np
  6. Ensure Make private key exportable is checked.
  7. Complete the enrollment.
Certificate Enrollment – Subject and SAN (Step 1)
Certificate Enrollment Subject SAN 1
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 2)
Certificate Enrollment Subject SAN 2
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 3)
Certificate Enrollment Subject SAN 3
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 4)
Certificate Enrollment Subject SAN 4
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 5)
Certificate Enrollment Subject SAN 5
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 6)
Certificate Enrollment Subject SAN 6
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 7)
Certificate Enrollment Subject SAN 7
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 8)
Certificate Enrollment Subject SAN 8
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 9)
Certificate Enrollment Subject SAN 9
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 10)
Certificate Enrollment Subject SAN 10
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 11)
Certificate Enrollment Subject SAN 11
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 12)
Certificate Enrollment Subject SAN 12
🖱️ Click image to view full size
Certificate Enrollment – Subject and SAN (Step 13)
Certificate Enrollment Subject SAN 13
🖱️ Click image to view full size

5. Step 4 – Install & Configure ADFS Role on Windows Server 2016

Now we will install the ADFS server role and configure the first federation server in a new farm.

5.1 Install the ADFS Role

On adfs-01.maharjan.np, open PowerShell as Administrator and run:

Install-WindowsFeature ADFS-Federation -IncludeManagementTools
PowerShell – ADFS role installation
PowerShell ADFS role installation
🖱️ Click image to view full size

After installation, reboot the server.

Reboot prompt
Reboot prompt
🖱️ Click image to view full size

5.2 Configure the Federation Service

After reboot, open Server Manager, click the notification flag, and select Configure the federation service on this server.

  1. Choose Create the first federation server in a federation server farm.
  2. Supply Domain Admin credentials.
  3. On the Service Account page, specify adfsGMSA (the gMSA we created).
  4. Select the SSL certificate with subject adfs.mhr.com.np.
  5. Set Federation Service Display Name to MAHARJAN ADFS.
  6. For Federation Service Name, enter adfs.mhr.com.np.
  7. Choose Windows Internal Database (WID) for the farm database (suitable for lab).
  8. Review settings and complete the wizard.
ADFS Configuration Wizard – Choose Farm
ADFS Wizard Choose Farm
🖱️ Click image to view full size
ADFS Configuration Wizard – Domain Admin
ADFS Wizard Domain Admin
🖱️ Click image to view full size
ADFS Configuration Wizard – Service Properties
ADFS Service Properties
🖱️ Click image to view full size
ADFS Configuration Wizard – Import ADFS SSL Certificate
Import ADFS SSL Certificate
🖱️ Click image to view full size
ADFS Configuration Wizard – Import ADFS SSL Certificate PFX Password
Import ADFS SSL Certificate PFX Password
🖱️ Click image to view full size
ADFS Configuration Wizard – FS Display Name
FS Display Name
🖱️ Click image to view full size
ADFS Configuration Wizard – Specify Service Account
Specify Service Account
🖱️ Click image to view full size
ADFS Configuration Wizard – Database (WID)
ADFS Wizard Database WID
🖱️ Click image to view full size
ADFS Configuration Wizard – Review Options
ADFS Wizard Review Options
🖱️ Click image to view full size
ADFS Configuration Wizard – Pre-requisite Checks
ADFS Wizard Pre-requisite Checks
🖱️ Click image to view full size
ADFS Configuration Wizard – Completion
ADFS Wizard Completion
🖱️ Click image to view full size

6. Verification – ADFS Endpoint

On the ADFS server (or a client with DNS resolution), open a browser and navigate to:

https://adfs.mhr.com.np/adfs/ls/idpinitiatedsignon.aspx

(Note: If you use the internal hostname adfs.maharjan.np, replace accordingly.)

⚠️ Important: On Windows Server 2016 and later, the IdP‑initiated sign‑on page is disabled by default for security reasons. To enable it (only for testing), run these PowerShell commands on the ADFS server:
# Check current status
Get-AdfsProperties | Select-Object EnableIdpInitiatedSignonPage

# Enable the page
Set-AdfsProperties -EnableIdpInitiatedSignonPage $true

After enabling, you should see the ADFS sign‑in page. Log in with a domain account (e.g., maharjan\administrator) and confirm successful authentication.

ADFS sign‑in page
ADFS sign-in page
🖱️ Click image to view full size
ADFS Service Check
ADFS Service Verify
🖱️ Click image to view full size

Your ADFS farm is now operational!

7. Troubleshooting Common Issues

  • Certificate not trusted: Ensure the CA root certificate is installed in the Trusted Root store on the ADFS server (domain members automatically trust it).
  • gMSA not found: Use the full service account name with trailing $ (e.g., maharjan\adfsGMSA$).
  • DNS resolution fails: Verify A-records for adfs.mhr.com.np and certauth.adfs.mhr.com.np point to the correct IP.
  • ADFS Sign-in Page Failure: Troubleshoot by checking the IdP‑initiated sign‑on status (Get-AdfsProperties) and verifying SSL certificate bindings using netsh http show sslcert and Get-AdfsSslCertificate.
  • Port 443 blocked: Check Windows Firewall and network security groups.
  • ADFS event logs: Check Applications and Services Logs → AD FS → Admin for detailed error messages.

🚀 Next Steps – Exchange OWA Federation

With the ADFS server now ready, we can proceed to integrate it with Exchange Server SE. In Part 4, we will:

  • ✅ Create Relying Party Trust for OWA
  • ✅ Configure claim rules for UPN and SID
  • ✅ Enable ADFS authentication on Exchange
  • ✅ Test the full SSO flow

Stay tuned for the next hands-on lab!

Start Part 4 Now

ADFS Mastery Series – Part 3: ADFS Server Installation

Leave a Reply

Your email address will not be published. Required fields are marked *