ADFS 2.0, Event ID - 186, Error : The Federation Service Could Not Fulfill

Query King | Wed, 28 Mar 2018 at 04:21 hours | Replies : 2 | Points : 100

Category : ADFS


Hi Friends,

I am getting event error 186 and after Adding new relaying party in ADFS 2.0 Server. Please help.

The Federation Service could not fulfill the token-issuance request. More than one claim based on SamlNameIdentifierClaimResource was produced after the issuance  transform rules were applies for relying party

 

Error Log details:

Log Name:     AD FS/Admin

Source:       AD FS

Date:         6/2/2018 10:18:20 AM

Event ID:     186

Task Category: None

Level:         Error

Keywords:     AD FS

User:         ABC\ADFS_SERVICEAC

Computer:     ADFS01.ABC

Description:

The Federation Service could not fulfill the token-issuance request. More than one claim based on SamlNameIdentifierClaimResource was produced after the issuance  transform rules were applies for relying party 'https://www.experts-adda.com'. See event 500 with the same Instance ID for claims after application of issuance transform rules.

 

Additional Data

Instance ID: 60f5ad6d-8122-4f29-a1b2-2ff471336b17

 

User Action

Ensure that the issuance transform rules that are configured for the relying party do not result in multiple claims based on SamlNameIdentifierClaimResource.


This Question is already solved Click To See The Answer


Hi,

 

Seems there is two similar claims are passing to Relaying party. Please see the event 500 for name of those "Claims".

  • Go to the Questioned Relaying party
  • Edit Claim Rules
  • Review and Remove duplicate claim rule and check.

Hope it helps.

 

Hi Santosh,

 

Thanks, Yes, I was getting Event 500, I found that 1 claims was sending duplicate value. I tried to remove but it wont work. Then after I have deleted entire claim rule and created new without any duplicate claim value.

 

Thanks aging for highlighting.

 

Event 500 Details.

Log Name:     AD FS/Admin

Source:       AD FS

Date:         6/2/2018 10:18:20 AM

Event ID:     500

Task Category: None

Level:         Information

Keywords:     AD FS

User:         ABC\ADFS_SERVICEAC

Computer:     ADFS01.ABC

Description:

More information for the event entry with Instance ID db16764e-0cd5-4ed4-92a2-d0b8010cc780. There may be more events with the same Instance ID with more information.

 

Instance ID:

db16764e-0cd5-4ed4-92a2-d0b8010cc780

 

 

Issued identity:

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn

SHARMAG

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier

SHARMAG

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier

hcl.guptask@abc

http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod

urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport

http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant

2018-02-06T02:18:16.730Z