PROBLEM
When a federated user tries to sign in to a Microsoft cloud service such as Office 365, Microsoft Azure, or Microsoft Intune, the user receives the following error message from Active Directory Federation Services (AD FS):When this error occurs, the web browser’s address bar points to the on-premises AD FS endpoint at an address that resembles the following:
There was a problem accessing the site. Try to browse to the site again.
If the problem persists, contact the administrator of this site and provide the reference number to identify the problem.
Reference number: <GUID>
If the problem persists, contact the administrator of this site and provide the reference number to identify the problem.
Reference number: <GUID>
https://sts.domain.com/adfs/ls/?cbcxt=&vv=&username=username%40domain.com&mkt=&lc=1033&wa=wsignin1.0&wtrealm=urn:federation:MicrosoftOnline&wctx=MEST%3D0%26LoginOptions%3D2%26wa%3Dwsignin1.0%26rpsnv%3D2%26ct%3D1299115248%26rver%3D6.1.6206.0%26wp%3DMCMBI%26wreply%3Dhttps:%252F%252Fportal.office.com%252FDefault.aspx%26lc%3D1033%26id%3D271346%26bk%3D1299115248
CAUSE
This issue may occur for one of the following reasons:
- The setup of single sign-on (SSO) through AD FS wasn't completed.
- The AD FS token-signing certificate expired.
- The AD FS client access policy claims are set up incorrectly.
- The relying party trust with Azure Active Directory (Azure AD) is missing or is set up incorrectly.
- The AD FS federation proxy server is set up incorrectly or exposed incorrectly.
- The AD FS IUSR account doesn't have the "Impersonate a client after authentication" user permission.
REFERENCES
For more information about how to troubleshoot sign-in issues for federated users, see the following Microsoft Knowledge Base articles: