Welcome to TechNet Blogs Sign in | Join | Help

Syndication

ADFS Diagnostic Tool

A huge thanks to the ADFS test team for developing such a great tool. 

 

Here is a quick "how to"

 

The tool is very simple to use and provides a graphical UI. In order to perform distributed diagnosis, i.e. diagnose failures based on the configuration of multiple machines in the scenario, it’s necessary to copy the out file generated by the tool each time it’s run and use it as an input/output file when running the tool on the next machine.

 

For example, to debug a scenario with an FS at the account role (FS-A), an FS at the resource role (FS-R) and a Web Server (WS), first run the tool on the FS-A selecting a new file, say adfsdiag.out. After the tool is run, this file will now contain configuration information relative to the FS-A. Copy the file to the FS-R machine and run the tool there, this time selecting the existing adfsdiag.out file. The tool will detect it already contains information relative to other roles and will execute extra configuration checks, for example, a claim flow check that verifies the outgoing claims sent by the FS-A match the incoming claims expected by the FS-R. After this second run, adfsdiag.out will contain information relative to both the FS-A and FS-R. Finally, copy the out file to the WS machine and run the tool again following the same steps. When running the tool for a role for which there’s already information present in the selected file, the old data for that role will be overwritten with the new information, making it possible to fix errors on a machine and re-run the tool without having to start the whole process all over again. There’s no “right order” to run the tool, all of them should give the same output, except for some certificate checks that will only be executed at the WS in case the information from the FS-R is available beforehand

 

Please give this tool a try and provide any feedback to this blog.

Published Thursday, November 01, 2007 2:44 PM by jimsim


Attachment(s): ADFSDiag.zip

Comments

# des on Federated Identity … less is more » Blog Archive » New Diagnostic Tool for Active Directory Federation Services @ Wednesday, January 30, 2008 11:11 PM

PingBack from http://identity-des.com/2008/01/30/new-diagnostic-tool-for-active-directory-federation-services/

des on Federated Identity … less is more » Blog Archive » New Diagnostic Tool for Active Directory Federation Services

# Need help Troubleshooting ADFS? Check out the ADFS Diag Tool... @ Monday, March 03, 2008 5:16 PM

It's no secret, troubleshooting ADFS can be tough. That's why a few key members from our ADFS Test Team

ADFS Documentation Blog

# ADFSDiag has been updated @ Tuesday, April 01, 2008 6:31 PM

A new version of the tool is now available... This version includes SharePoint / MOSS support: the UI

ADFS Product Support Blog

# re: ADFS Diagnostic Tool @ Wednesday, April 09, 2008 7:23 PM

I can't tell you how much this tool saved me, I was troubleshooting for hours and I would have never figured out the issues without this tool.  Thanks so much for writing and publishing it!

heinsonw

# ADFSDiag.exe has stopped working @ Monday, June 23, 2008 6:37 AM

Is ADFS Diag supported for Windows 2008 Enterprise edition 64-bit?

Peter Geelen

# re: ADFS Diagnostic Tool @ Tuesday, June 24, 2008 7:49 PM

Hi Peter,

ADFSDiag should work on 2008 64bit...

What error are you getting?

jimsim

# re: ADFS Diagnostic Tool @ Friday, June 27, 2008 7:00 AM

Hi Peter,

I have put the 64bit version up on the site - this should resolve your issue

http://blogs.technet.com/adfs/archive/2008/02/18/adfs-diagnostic-tool-64-bit.aspx

jimsim

# ADFSDiag has been updated again! @ Thursday, December 11, 2008 12:19 PM

The updated tool can be found here . The attachment contains both 32 and 64 bit installers. A cool new

ADFS Product Support Blog

# re: ADFS Diagnostic Tool @ Friday, January 09, 2009 4:22 PM

I used this tool before in Windows 2003 and it was very helpful.

I have upgraded my test environment to 2008.  I am running this on the server where the federated services are install (not the proxy, though that is what I wanted to test next).

I am getting an exception:

Exception thrown while performing IIS Observation:

 Exception: Microsoft.Test.Product.IIS

 Message: Cannot process ssl cert -- certificate hash is null

I don't have any problems using the certificate.

Any thoughts on what I have done wrong?

Regards

Frank

Frank Postle

Anonymous comments are disabled
Page view tracker