Saturday, October 23, 2010

Display ADFS 2.0 Forms Authentication Login Page Instead of Windows Authentication Prompt

After installing ADFS 2.0 for SharePoint a Windows login prompt was shown when the SharePoint site forwarded to the ADFS server instead of the ADFS Forms Authentication login screen. 



No matter what account I tried to use here I would eventually receive a 401 Not Auhorized error.




The reason for this is that the ADFS website tries to use Windows Authentication before trying to use the Forms authentication which displays the loging page below.


Forms Login Screen for ADFS 2.0


To fix this do the following on the ADFS server:

1. Open IIS and Explore under Default Website\adfs\ls


2. Open the web.config file with Notepad, look for the localAuthenticationTypes section.



3. Move the line for Forms above the line for Integrated and save the web.config file.  This will force the ADFS application to use the Login Page authentication before trying to use Windows Authentication.


 

13 comments:

Superpat said...

Thanks for posting this - it fixed exactly the problem I was having in being able to show the difference between form-based authn and IWA.

Job Vermeulen said...

But now users that could use SSO with Windows Auth. get the Forms login too.

This is no solution to mix.

Dude said...

This is set in the web.config, the wsFederation node: authenticationType.

SMFX said...

Thanks for the info! Never thought about the XML order being relavent.

I was actually having the inverse issue where internal users would get Integrated Auth and external would have Forms from the ADFS Proxy. Moving the basic before the forms on the Proxy gives them a similar experience.

Thanks!

harminder datla said...

hi ,

i am getting an exception 404 not found
please help me to rresolve this, i have already done web config changes.

thanks
harminder datla

Unknown said...

I want to add two pages for FormsSignIn
one is for normal browser, another is for mobile browser.
Can I add two in web.config

Pradeep Kumar said...

Hi Richard,

Is it possible for adfs server to use Forms authentication or we have to take adfs server proxy for Forms Authentication ?

Thanks in advance
Pradeep Kumar

Jeff Kyker said...

AMAZING! So easy to do! Just so hard to find. I gave one more effort to find a solution this morning and landed on yours and it worked instantly. Thank you sooo much.

Eugene said...

Thanks.

This wasn't my exact issue but got me going in the right direction on my issue.

yahoo said...

it works perfectly. Thanks a lot

Simon de Lisle said...

Fantastic - 2 days of trying to figure this out and a guy gives me a link to this page and BANG! Sorted.

Thanks for taking the time to document this so clearly.

Amogh Natu said...

Thank you so much. This helped me resolve my problem.

翁哲 said...

Thanks Richard.

By the way, is there a way we can have the signed in windows users auto-login to the websites?