Internet-based client computers can't authenticate after you set up Active Directory Federation Services (AD FS) in a "firewall-published" configuration

Article translations Article translations
Article ID: 2535789 - View products that this article applies to.
Expand all | Collapse all


When you try to set up Active Directory Federation Services (AD FS) in a "firewall-published" configuration, Internet-based client computers can't authenticate by using a federated user account. However, a client computer that resides on the on-premises network can successfully authenticate to Office 365 resources by using a federated user account.

The firewall-published configuration uses a firewall device, such as Microsoft Threat Management Gateway (TMG), to reverse proxy the AD FS Federation Service directly to the Internet. For more information about how to configure AD FS in a firewall-published configuration, click the following article number to view the Microsoft Knowledge Base article:
2510193 Supported scenarios for using AD FS to set up single sign-on in Office 365, Windows Azure, or Windows Intune
Additionally, when the Internet-based client computer tries to authenticate to the on-premises AD FS Federation service endpoint name, such as, one or more of the following issues occurs:
  • You're repeatedly prompted to log on (more than three times) without a successful authentication.
  • Access is denied, even though you enter valid Active Directory credentials.
  • "403 page not found" errors occur.


This issue occurs when the service requirements for publishing AD FS through a firewall limit a client device’s HTTP access to the AD FS Federation service. In this case, one or more of the following conditions are true:
  • Extended Protection for Authentication (EPA) may not be disabled on the AD FS Federation Server farm.
  • Firewall reverse proxy rule features may have been enabled that disrupt normal AD FS connection and functionality.


Disable Extended Protection Authentication for AD FS

Extended Protection Authentication (EPA) is a feature that's used by AD FS to detect man-in-the middle attacks. When a firewall is proxying the connection to the AD FS server, EPA may identify the firewall proxy as an attack. For information about how to disable this feature, see the following Microsoft Knowledge Base article:
2461628  A federated user is repeatedly prompted for credentials during sign-in to Office 365, Windows Azure, or Windows Intune
Firewall proxy rule configuration may be limiting connectivity

Note The following information is only advisory and may help resolve the problem, but it's offered without guarantee:


Still need help? Go to the Office 365 Community website or the Windows Azure Active Directory Forums website.


Article ID: 2535789 - Last Review: March 6, 2014 - Revision: 23.0
Applies to
  • Windows Azure
  • Microsoft Office 365
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • CRM Online via Office 365 E Plans
  • Windows Azure Recovery Services
o365 o365a o365e o365062011 pre-upgrade o365022013 after upgrade o365m KB2535789

Give Feedback


Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from