ADFS 2.0, Event ID - 186, Error : The Federation Service Could Not Fulfill
Query King | Wed, 28 Mar 2018 at 04:21 hours | Replies : 2 | Points : 100
Category : ADFS
Hi Friends,
I am getting event error 186 and after Adding new relaying party in ADFS 2.0 Server. Please help.
The Federation Service could not fulfill the token-issuance request. More than one claim based on SamlNameIdentifierClaimResource was produced after the issuance transform rules were applies for relying party
Error Log details:
Log Name: AD FS/Admin
Source: AD FS
Date: 6/2/2018 10:18:20 AM
Event ID: 186
Task Category: None
Level: Error
Keywords: AD FS
User: ABC\ADFS_SERVICEAC
Computer: ADFS01.ABC
Description:
The Federation Service could not fulfill the token-issuance request. More than one claim based on SamlNameIdentifierClaimResource was produced after the issuance transform rules were applies for relying party 'https://www.experts-adda.com'. See event 500 with the same Instance ID for claims after application of issuance transform rules.
Additional Data
Instance ID: 60f5ad6d-8122-4f29-a1b2-2ff471336b17
User Action
Ensure that the issuance transform rules that are configured for the relying party do not result in multiple claims based on SamlNameIdentifierClaimResource.
This Question is already solved Click To See The Answer
Hi,
Seems there is two similar claims are passing to Relaying party. Please see the event 500 for name of those "Claims".
- Go to the Questioned Relaying party
- Edit Claim Rules
- Review and Remove duplicate claim rule and check.
Hope it helps.
Hi Santosh,
Thanks, Yes, I was getting Event 500, I found that 1 claims was sending duplicate value. I tried to remove but it wont work. Then after I have deleted entire claim rule and created new without any duplicate claim value.
Thanks aging for highlighting.
Event 500 Details.
Log Name: AD FS/Admin
Source: AD FS
Date: 6/2/2018 10:18:20 AM
Event ID: 500
Task Category: None
Level: Information
Keywords: AD FS
User: ABC\ADFS_SERVICEAC
Computer: ADFS01.ABC
Description:
More information for the event entry with Instance ID db16764e-0cd5-4ed4-92a2-d0b8010cc780. There may be more events with the same Instance ID with more information.
Instance ID:
db16764e-0cd5-4ed4-92a2-d0b8010cc780
Issued identity:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn
SHARMAG
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
SHARMAG
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
hcl.guptask@abc
http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant
2018-02-06T02:18:16.730Z