web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

User Access upgraded org from 2013 > 2013 sp1 > 2015 >2016

(0) ShareShare
ReportReport
Posted on by 30

Hello,

I have been practicing my upgrade from 2013 to 2016 and everything seems to be going pretty well, except for user's getting adfs errors when they try to login to the 2016 imported org.

If I disable ADFS, then they seem to be able to login fine.  The real key for me is that I found a way to "fix" their users.

Basically, I have 3 migration servers.  1 is 2013 sp1, 1 is 2015, and the last is 2016.  The 2016 is where the org will finally rest.  As part of building my migration servers I created default orgs on all of these systems.  That was a requirement to even install dynamics on a new server.  Let's call this org on the 2016 server "default2016org".  Let's call my original 2013 prod org/db "2013prod"

When I finally get my "2013prod" imported all the way to my 2016 server, users have problems.  They get a generic ADFS error on the new 2016 server.  Well, all user's except mine.  I finally realized that my user was a member of the "default2016org".  So, as a test, I put the imported users on my now upgraded "2013prod" org into the "default2016org" and they could suddenly login to the "2013prod" org.

My Guess is that the imported users are not part of the right funky groups that get created with every Dynamics build, and therefore are getting denied access, until I put them in the default org, which adds them to those groups. 

My question is, how do I avoid this issue?  I have never found a great way to import users from one org to another, and I'm not sure that I want to leave the "default2016org" around or have to add all the users to it.  I also have a suspicion that any new users I add to the upgraded "2013prod" org won't work unless I add them to the "default2016org"

thanks

*This post is locked for comments

I have the same question (0)
  • razdynamics Profile Picture
    17,308 User Group Leader on at

    Hi Sam, so it looks like your using the same AD groups, didn't u create new AD orgs for your CRM 2016 installation?

  • Sam F Profile Picture
    30 on at

    Hi Raz, thanks for the reply,

    I did create new groups on the 2016 installation.  I actually blew away my 2016 config, groups, db, etc and built it again today.  I imported my db from 2015 to 2016, everything looks good, and users can even login.  Then, I setup adfs and users can't login, except for me, because I'm also a user in the default 2016 org.  Once I put a user in the default org then they can login to my imported org just fine with adfs enabled.

    It appears to be an adfs error and I've pasted the event log errors below when a user can't authenticate.  The problem is, that I can fix the adfs authentication by adding the user to the default 2016 org.  Do I need to upgrade adfs, is there some simple setting I'm missing?  Thank You

    p.s. I have looked up these adfs errors and haven't been able to find a fix.

    Encountered error during federation passive request.

    Additional Data

    Protocol Name:

    wsfed

    Relying Party:

     

    Exception details:

    Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The same client browser session has made '6' requests in the last '1' seconds. Contact your administrator for details.

      at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.UpdateLoopDetectionCookie(WrappedHttpListenerContext context)

      at Microsoft.IdentityServer.Web.Protocols.WSFederation.WSFederationProtocolHandler.SendSignInResponse(WSFederationContext context, MSISSignInResponse response)

      at Microsoft.IdentityServer.Web.PassiveProtocolListener.ProcessProtocolRequest(ProtocolContext protocolContext, PassiveProtocolHandler protocolHandler)

     

    System

    -

    Provider

    [ Name]

    AD FS

    [ Guid]

    {2FFB687A-1571-4ACE-8550-47AB5CCAE2BC}

    EventID

    364

    Version

    0

    Level

    2

    Task

    0

    Opcode

    0

    Keywords

    0x8000000000000001

    -

    TimeCreated

    [ SystemTime]

    2016-02-15T20:20:11.274638300Z

    EventRecordID

    7449

    -

    Correlation

    [ ActivityID]

    {00000000-0000-0000-8500-0080000000E1}

    -

    Execution

    [ ProcessID]

    2676

    [ ThreadID]

    5964

    Channel

    AD FS/Admin

    Computer

    adfs.mydomain.com

    -

    Security

    [ UserID]

    S-1-5-21-3141563952-2487314046-1202279143-19567

    -

    UserData

    -

    Event

    -

    EventData

    Data

    wsfed

    Data

    Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The same client browser session has made '6' requests in the last '1' seconds. Contact your administrator for details. at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.UpdateLoopDetectionCookie(WrappedHttpListenerContext context) at Microsoft.IdentityServer.Web.Protocols.WSFederation.WSFederationProtocolHandler.SendSignInResponse(WSFederationContext context, MSISSignInResponse response) at Microsoft.IdentityServer.Web.PassiveProtocolListener.ProcessProtocolRequest(ProtocolContext protocolContext, PassiveProtocolHandler protocolHandler) at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)

     

      at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)

    System

    -

    Provider

    [ Name]

    AD FS

    [ Guid]

    {2FFB687A-1571-4ACE-8550-47AB5CCAE2BC}

    EventID

    364

    Version

    0

    Level

    2

    Task

    0

    Opcode

    0

    Keywords

    0x8000000000000001

    -

    TimeCreated

    [ SystemTime]

    2016-02-15T20:20:11.274638300Z

    EventRecordID

    7449

    -

    Correlation

    [ ActivityID]

    {00000000-0000-0000-8500-0080000000E1}

    -

    Execution

    [ ProcessID]

    2676

    [ ThreadID]

    5964

    Channel

    AD FS/Admin

    Computer

    adfs.mydomain.com

    -

    Security

    [ UserID]

    S-1-5-21-3141563952-2487314046-1202279143-19567

    -

    UserData

    -

    Event

    -

    EventData

    Data

    wsfed

    Data

    Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The same client browser session has made '6' requests in the last '1' seconds. Contact your administrator for details. at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.UpdateLoopDetectionCookie(WrappedHttpListenerContext context) at Microsoft.IdentityServer.Web.Protocols.WSFederation.WSFederationProtocolHandler.SendSignInResponse(WSFederationContext context, MSISSignInResponse response) at Microsoft.IdentityServer.Web.PassiveProtocolListener.ProcessProtocolRequest(ProtocolContext protocolContext, PassiveProtocolHandler protocolHandler) at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)

     

     

  • Sam F Profile Picture
    30 on at

    Ok, so I'm not sure if this fixed it, and I'm not sure what will happen with my other orgs once they are imported but...

    I deleted the default org "default2016org" which  made my imported org the default for that dynamics 2016 installation and now it seems my users can login via adfs.

    Can anyone explain to me what is happening here?  Am I going to see problems with my other orgs once they are imported?

    Thanks

  • Verified answer
    Sam F Profile Picture
    30 on at

    Well, That was it.  I had to delete the default org that I created when I installed my 2016 dynamics server.  My primary and secondary org logins now work just fine with adfs authentication enabled.  I'm adding this so other people know, but it would be nice to get any input from someone who knows anything about dynamics/adfs as to why it was broken and why that fixed it :).

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
SA-08121319-0 Profile Picture

SA-08121319-0 4

#1
Calum MacFarlane Profile Picture

Calum MacFarlane 4

#3
Alex Fun Wei Jie Profile Picture

Alex Fun Wei Jie 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans