Hi mates. Today we’re going to cover how to investigate and fix WAP Trust error Service Unavailable when AD FS endpoint /adfs/proxy/establishTrust/ is not available.
Overview
The endpoint /adfs/proxy/establishTrust/ is used by the WAP server to establish the trust during the post-install process. When this endpoint is not available, you might face error message below during a WAP trust configuration:
PowerShell Error message: cmdlet Install-WebApplicationProxy at command pipeline position 1
Supply values for the following parameters: FederationServiceTrustCredential
Install-WebApplicationProxy : An error occurred when attempting to establish a trust relationship with the federation service. Error: Service Unavailable
At line:1 char:1
+ Install-WebApplicationProxy -FederationServiceName fs.contoso. …
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [Install-WebApplicationProxy], ProxyTrustException
+ FullyQualifiedErrorId
DeploymentTask,Microsoft.IdentityServer.Management.Proxy.Commands.InstallProxyCommand

With AD FS tracing debug logs enabled, you might see event IDs 12, 57 and 104 on the WAP server as below:
WAP server: AD FS Tracing/Debug
Source: AD FS Tracing
Event ID: 12
Task Category: None
Level: Error
Keywords: ADFSConfiguration
Description:
Error: Exception: An error occurred when attempting to establish a trust relationship with the federation service. Error: Service Unavailable
StackTrace: at Microsoft.IdentityServer.Management.Proxy.Providers.ProxyTrustProvider.EstablishTrustWithSts(ICredentials credentials, String thumbprint) at Microsoft.IdentityServer.Deployment.Core.Tasks.ConfigurationTaskBase.Execute(IDeploymentContext context, IProgressReporter progressReporter)
Exception: The remote server returned an error: (503) Server Unavailable.
StackTrace: at System.Net.HttpWebRequest.GetResponse() at Microsoft.IdentityServer.Management.Proxy.Providers.ProxyTrustProvider.EstablishTrustWithSts(ICredentials credentials, String thumbprint)
AD FS server: AD FS Tracing/Debug
Source: AD FS Tracing
Event ID: 107
Task Category: None
Level: Error
Keywords: ADFSProxyConfiguration
Description:
ProxyConfigurationListener.OnGetContext: There were no registered handlers to handle the request to : ‘’.
Log Name: AD FS Tracing/Debug
Source: AD FS Tracing
Event ID: 54
Task Category: None
Level: Information
Keywords: ADFSSTS
Description:
Sending response at time: ‘2021-01-27 11:00:23’ with StatusCode: ‘503’ and StatusDescription: ‘Service Unavailable’.
Response headers set: {“Content-Type”:”text/html; charset=utf-8″}
Cause:
WAP trust is established by posting a client certificate to the AD FS “Proxy” endpoint. : /adfs/proxy/establishTrust/ and this endpoint should be accessible from WAP server.
Troubleshooting steps:
Checking AD FS Proxy Trust Endpoint status
Check if endpoint /adfs/Proxy/EstablishTrust/ is enabled on the primary AD FS running following command:
Get-AdfsEndpoint -AddressPath '/adfs/Proxy/EstablishTrust/'
If endpoint is disabled, you might see output below:
ClientCredentialType : Username-Password-Clear
Enabled : False
FullUrl : https://fs.contoso.com/adfs/proxy/EstablishTrust/
Proxy : False
Protocol : Web Application Proxy
SecurityMode : Transport
AddressPath : /adfs/proxy/EstablishTrust/
Version : default
Enabling endpoint /adfs/proxy/EstablishTrust/
Run commands below to enable the endpoint on the AD FS server. The AD FS service restart is required to take effect:
Enable-AdfsEndpoint -TargetAddressPath '/adfs/Proxy/EstablishTrust/' Restart-Service adfssrv
Run again the command Install-WebApplicationProxy to re-establish the trust as example below:
Note: Considering the federation service name is fs.contoso.com and the SSL certificate thumbprint is 3638de9b03a488341dfe32fc3ae5c480ee687793.
Install-WebApplicationProxy -FederationServiceName fs.contoso.com -CertificateThumbprint "3638de9b03a488341dfe32fc3ae5c480ee687793"
Summary
In this article, we covered how to investigate and fix WAP trust issues related to the endpoint ‘/adfs/Proxy/EstablishTrust/’.
I hope you have enjoyed reading this article and it helps you manage your AD FS environment.
Enjoyed the article? Like and share. 🙂
Note: I do not represent the organization I work for, all the opinions expressed here, are my own. This post is provided AS IS with no warranties or guarantees and confers no rights.
In case you have any suggestion or feedback, please leave a comment.
[ ]’s
Ulysses Neves
