AD FS Logon Page Graphics

Two Planker 111 Reputation points
2021-10-13T20:20:22.99+00:00

Greetings,

I've deployed an AD FS server successfully in an isolated environment (no Internet). When I get to the AD FS logon page, there are no graphics, just text and related fields. I'm not having any luck finding a resolution. The system works properly otherwise.

Has anyone experienced this?

Thanks,

Chris

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,389 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,661 questions
0 comments No comments
{count} votes

Accepted answer
  1. Two Planker 111 Reputation points
    2021-11-16T17:07:03.313+00:00

    Sikumars,

    after breaking and troubleshooting ADFS after a backup, uninstall, re-install and restore, I have found a workaround here:

    https://social.technet.microsoft.com/Forums/Lync/en-US/2df3ef95-b0e1-4a89-96ce-3fd4edd7a7f9/failed-to-start-endpoint-https49443adfsportal?forum=ADFS

    I've added my Group Managed Service Account to the local admins group and now the graphics on the logon page appear. I've also tried the "fix" described by one of the users yet it does not work. Only adding the gmsa to the admins group allows the site to present normally.

    I may not be applying the fix properly as I don't quite understand all that he is referring to. I tried modifying the url acl permission for https://+:443/adfs by deleting the existing perms for User: NT SERVICE\adfssrv and adding my gmsa service account yet there was no change after restarting services.

    Does this make sense to you?

    I apologize if I don't reply to any responses as I'm leaving town for about a week.

    Thanks for the help,

    TP

    1 person found this answer helpful.

10 additional answers

Sort by: Most helpful
  1. Two Planker 111 Reputation points
    2021-11-16T17:15:02.7+00:00

    A quick update,

    I removed the gmsa account from the admin group and restarted the adfs server. The logon page graphics are still present. Wondering if the fix actually worked and the server just needed restarting or did adding/removing the gmsa account from the admin group was all that was needed.

    TP

    2 people found this answer helpful.

  2. Rich Matheisen 45,096 Reputation points
    2021-10-13T21:05:05.52+00:00
    0 comments No comments

  3. Limitless Technology 39,391 Reputation points
    2021-10-15T09:34:38.61+00:00

    Hi there,

    When a federated user tries to sign in to a Microsoft cloud service such as Office 365, Microsoft Azure, or Microsoft Intune, the Internet browser can't display the Active Directory Federation Services (AD FS) sign-in webpage. Additionally, the user may receive an error message.

    This issue may occur if the user can't contact the on-premises AD FS federation server or the Internet-facing AD FS Federation server proxy. This can occur when the AD FS Federation Service stops running or when IP connectivity is marginalized.

    You can try the following steps https://learn.microsoft.com/en-us/office365/troubleshoot/sign-in/ad-fs-sign-in-page-not-display

    ------------------------------------------------------------------------------------------------------------------------------------

    If the reply is helpful, please Upvote and Accept it as an answer


  4. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2021-10-18T12:22:37.187+00:00

    @Two Planker Since you mentioned that you configured that in an isolated environment, make sure that the machine on which you are trying has the ADFS url in local intranet zone of internet explorer.

    Follow this if you need step by step method : https://learn.microsoft.com/en-us/dynamics365/customerengagement/on-premises/deploy/add-the-ad-fs-website-to-the-local-intranet-security-zone?view=op-9-1

    Let me know if this helps, we can also take this offline to understand more and help.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.