Rebuild ADFS Server Farm

Marcus Wong Theen Nam 1,111 Reputation points
2021-01-18T11:11:02.24+00:00

We have a 2008 R2 ADFS server farm where all the nodes inside the farm were corrupted and unable to bring up anymore. So we are thinking to rebuild the new ADFS server farm in 2008 R2/ 2012 R2. We have the below question before proceeding to the installation:

  1. How to manually cleanup the ADFS config in Active Directory as we have no access to the corrupted ADFS nodes anymore?
  2. Can we configure the new ADFS server farm with the same Federation Service Name as previous corrupted adfs server farm?
  3. Can we reuse the previous service account that was being used by corrupted adfs server farm?

Thank you.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,198 questions
0 comments No comments
{count} votes

Accepted answer
  1. Abhijeet-MSFT 541 Reputation points Microsoft Employee
    2021-01-20T06:30:59.973+00:00

    HI @MarcusWong-9726 ,

    Please find answers inline.

    How to manually cleanup the ADFS config in Active Directory as we have no access to the corrupted ADFS nodes anymore?
    All information related to ADFS is stored in local config database. The only thing you need to clear in AD is the machine account and service principal.

    Can we configure the new ADFS server farm with the same Federation Service Name as previous corrupted adfs server farm?
    Yes. You can use the same federation name. Make sure to have the correct DNS pointing.

    Can we reuse the previous service account that was being used by corrupted adfs server farm?
    Yes. Make sure you remove the old SPN's added (if delegation is being used) and add new SPN's to the service account.

    0 comments No comments

0 additional answers

Sort by: Most helpful