Event Id | 727 |
Source | Microsoft-Windows-ADFS |
Description | The Federation Service has detected that Secure Sockets Layer (SSL) is not enabled for communication between this federation server and the server hosting the Active Directory Lightweight Directory Services (AD LDS) account store, identified by URI: %1, that you specified in the trust policy. Although communications between a federation server and an AD LDS server will be successful when a secure channel has not been established, we recommend that you configure the properties of your AD LDS account store using SSL unless this communication has already been secured by other means, such as Internet Protocol security (IPsec). |
Event Information | According to Microsoft : Cause This event is logged when the Federation Service has detected that Secure Sockets Layer (SSL) is not enabled for communication between this federation server and the server hosting the Active Directory Lightweight Directory Services (AD LDS) account store, identified by URI. Resolution Enable TLS and SSL configuration in the trust policy Ensure that communication between this federation server and the Active Directory Lightweight Directory Services (AD LDS) server is secure. You can use the Active Directory Federation Services snap-in to edit the properties of your AD LDS account stores and to configure them to use a secure channel. To perform this procedure, you must be a member of the local Administrators group, or you must have been delegated the appropriate authority. To enable a secure-channel configuration: 1.Click Start, point to Administrative Tools, and then click Active Directory Federation Services. 2.In the console tree, under Federation Service\Trust Policy\My Organization\Account Stores, right-click the AD LDS account store, and then click Properties. 3.Select the Enable TLS/SSL protocols check box, and then click OK. 4.Repeat these steps for each AD LDS account store in the trust policy. Verify Verify that you can access the Active Directory Federation Services (AD FS)-enabled application from a client browser and that the resource can be accessed. |
Reference Links | Event ID 727 from Source Microsoft-Windows-ADFS |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.