Error message after you run the MOSDAL Support Toolkit: "The Windows Integrated Authentication endpoint is missing from the Metadata Exchange (MEX) document that is published by the federation server"

Article translations Article translations
Article ID: 2707356 - View products that this article applies to.
Expand all | Collapse all

PROBLEM

After you run the Microsoft Online Services Diagnostics and Logging (MOSDAL) Support Toolkit, the Active Directory Federation Services (AD FS) diagnostics log contains the following error message:

The Windows Integrated Authentication endpoint is missing from the Metadata Exchange (MEX) document that is published by the federation server.

Note This log located at \Admin_Applications\SSO_Diagnostic_Tests\ADFSDiagnostic.txt.

Additionally, you may notice the following behavior when you sign in to your Microsoft cloud service such as Office 365, Windows Azure, or Windows Intune by using a federated account:

Rich client application authentication fails when it tries to access services from an on-premises Active Directory Domain Services-connected client computer.

CAUSE

This issue may occur if the windowstransport and usernamemixed service endpoints are disabled in the on-premises AD FS Federation service.

SOLUTION

To resolve this issue, make sure that the AD FS service endpoints are set to support single sign-on (SSO) authentication. For more information about how to do this, see the following Microsoft Knowledge Base article:
2712957 Sign in to Office 365, Windows Azure, or Windows Intune fails after you change the federation service endpoint   
After you update the service endpoints, make sure that the AD FS service endpoint configuration metadata is updated to the Windows Azure Active Directory (Windows Azure AD) authentication system. For more information about how to do this, see the "How to update the configuration of the Office 365 federated domain" section of the following Microsoft Knowledge Base article:
2647048 How to update or to repair the configuration of the Office 365 federated domain

MORE INFORMATION

Still need help? Go to the Office 365 Community website or the Windows Azure Active Directory Forums website.

Properties

Article ID: 2707356 - Last Review: January 14, 2014 - Revision: 15.0
Applies to
  • Windows Azure
  • Microsoft Office 365
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • CRM Online via Office 365 E Plans
  • Windows Azure Recovery Services
Keywords: 
o365 o365a mosdal4.5 o365022013 after upgrade o365062011 pre-upgrade o365e o365m KB2707356

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com