Event ID 122 — Windows NT Token-Based Application Configuration

Updated: December 3, 2008

Applies To: Windows Server 2008 R2

red

Web Agent for Windows NT token-based application configuration contains information about the AD FS Web Agent Authentication Service, creation of Windows NT tokens, and Windows token-based agent authentication requests.

Event Details

Product: Windows Operating System
ID: 122
Source: Microsoft-Windows-ADFS
Version: 6.1
Symbolic Name: SSO_METABASE_QUERY_FS_URL_FAILURE
Message: The AD FS Web Agent for Windows NT token-based applications did not find the Uniform Resource Locator (URL) for the Federation Service in the Internet Information Services (IIS) configuration.

The Web agent will not be able to generate Windows NT tokens for users until it can find the Federation Service URL. Claims-aware applications are not affected by this condition.

User Action
Ensure that the Federation Service URL is configured in the IIS Manager Web Sites property page.

Resolve

Configure the proper Federation Service URL in the IIS Manager snap-in

Ensure that the Federation Service Uniform Resource Locator (URL) is configured correctly in the IIS Manager snap-in.

To perform this procedure, you must be a member of the local Administrators group, or you must have been delegated the appropriate authority.

To check the URL for the Federation Service:

  1. On the Web server, click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager snap-in.
  2. In the console tree, click ComputerName.
  3. In the center pane, double-click Federation Services URL, and then ensure that the URL is configured correctly.

Verify

Verify that you can access the Active Directory Federation Services (AD FS)-enabled application from a client browser and that the resource can be accessed with the appropriate authorization.

If you cannot access the application successfully, verify that the Windows token-based agent is configured with correct URL values and that all configuration parameters contain valid values.

To perform this procedure, you must be a member of the local Administrators group, or you must have been delegated the appropriate authority.

To verify that the Windows token-based agent is configured with correct values:

  1. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager.
  2. In the console tree, click YourComputerName(local computer).
  3. In the console tree, double-click Sites, and then click YourWebSiteName.
  4. In the center pane, double-click Authentication, highlight AD FS Windows Token-Based Agent, and then in the Actions pane click Edit.
  5. In the AD FS Windows Token-Based Agent dialog box, confirm that the Enable AD FS Web Agent check box is selected.
  6. Make sure that the following values are valid, and then click OK.
    • Cookie path
    • Cookie domain
    • Return URL

Related Management Information

Windows NT Token-Based Application Configuration

Active Directory Federation Services

Community Additions

ADD
Show: