# Ulysses Neves > Microsoft Entra ID, authentication, and hybrid identity troubleshooting. ## Posts - [Microsoft Entra Privileged Identity Management (PIM) - Monitoring Privileged Access with Alerts and Event History](https://ulyssesneves.com/2019/10/15/azure-ad-pim-monitorando-o-acesso-privilegiado-com-alertas-e-historico-de-eventos/): In today's article, we'll show you how to monitor the activity related to requesting and granting privileged access using alerts and events in PIM. - [Microsoft Entra Privileged Identity Management (PIM) - Configuring Access Review](https://ulyssesneves.com/2019/10/07/azure-ad-pim-configurando-revisao-de-acesso/): Hello, everyone. In today's article, we'll talk about another topic from the AZ-500 – Microsoft Azure Security Technologies exam, "Configuring access reviews" and explain what it is and how to perform an access review for security groups in Microsoft Entra ID using PIM. - [Microsoft Entra Privileged Identity Management (PIM) - Controlling privileged access](https://ulyssesneves.com/2019/09/29/azure-ad-pim-controlando-o-acesso-privilegiado/): Hi everyone. In today's article, we'll show the workflow for requesting privileged access to a Microsoft Entra ID group managed by PIM. - [Microsoft Entra Privileged Identity Management (PIM) - Enabling PIM](https://ulyssesneves.com/2019/09/23/azure-ad-pim-privileged-identity-management/): In today's article, we'll introduce Microsoft Entra Privileged Identity Management (PIM) and explain step by step how to enable this feature to manage access to Azure resources and to Microsoft Entra ID as well. - [Meetup - Microsoft Azure + Microsoft 365](https://ulyssesneves.com/2019/09/21/meetup-microsoft-azure-microsoft-365/): Hello everyone. Stopping by to share a #Meetup I presented with my friend and Azure MVP mentor Jefferson Castilho from the blog http://jeffersoncastilho.com.br/ about Microsoft Azure and Microsoft 365 for employees of Itaú bank. - [Microsoft Entra Connect Sync – Filtering objects by OU](https://ulyssesneves.com/2019/09/16/azure-ad-connect-sync-filtrando-objetos-por-ou/): In today's article, we'll bring a brief step-by-step guide on how to create a filter on the objects synchronized to Microsoft Entra ID using OU (Organizational Units). - [Microsoft Entra Connect – Custom Installation – Step by Step](https://ulyssesneves.com/2019/09/11/azure-ad-connect-instalacao-personalizada-passo-a-passo/): In today's article, we'll perform the Microsoft Entra Connect installation with the custom option, using the PTA (pass-through authentication) method, which validates every attempt to access Azure services against the domain controllers on the internal network. - [Microsoft Entra Connect – Express Settings – Step by Step](https://ulyssesneves.com/2019/09/02/azure-ad-connect-configuracao-expressa-passo-a-passo/): In today's article, we'll install AD Connect using the simplest method, and the one used in most hybrid identity management implementations with Azure AD: the express installation. - [Microsoft Entra ID – Introduction to Microsoft Entra Connect](https://ulyssesneves.com/2019/08/28/azure-ad-introducao-ao-ad-connect/): In today's article, we'll cover a bit about the Microsoft Entra Connect tool, explain the services that are part of this solution, and the synchronization service architecture it uses - [Microsoft Entra ID – Custom Domains and Directories](https://ulyssesneves.com/2019/08/24/azure-ad-dominios-customizados-e-diretorios/): Continuing our Azure series, in today's article we'll cover custom domains and directories in Microsoft Entra ID. We'll show how to register a custom domain, the improvements this configuration brings, and how to work with directories in Microsoft Entra ID. - [Azure - Role-based access control (RBAC)](https://ulyssesneves.com/2019/08/20/azure-role-based-access-control-rbac/): In today's article, we'll introduce Azure RBAC (Role-based Access Control), what it's used for, how to customize roles, and how to assign roles to a user using the portal and PowerShell. - [Microsoft Entra ID - Introduction](https://ulyssesneves.com/2019/08/07/azure-ad-introducao/): In today's post, we talked about Microsoft Entra ID concepts, its plan options, and the difference between Microsoft Entra ID and on-premises AD. - [Azure Access Control - Step by Step](https://ulyssesneves.com/2019/08/02/azure-access-control-passo-a-passo/): Hello, everyone. Continuing our series on Azure resource security, we’ll talk about the access control feature in Azure, Identity Access Management (IAM), and demonstrate how to grant access to resources in Azure using the portal as well as PowerShell. What Is Identity Access Management (IAM)? Azure access control, better known as IAM, has the same functions as RBAC (Role-based Access Control), but it controls access to resources, resource groups, and subscriptions in Azure. Having an account in Microsoft Entra ID does not guarantee access to the resources available on this platform. To access Azure resources, you need to use RBAC (IAM)… - [Azure Resource Locks](https://ulyssesneves.com/2019/07/29/azure-resource-locks/): In today's post we cover Azure resource lock, which makes it possible to protect resources and resource groups from improper removal or modification. - [Creating a Resource Group using PowerShell and Azure CLI](https://ulyssesneves.com/2019/07/28/criando-resource-group-usando-powershell-e-azure-cli/): In today's post, we showed how to create and delete Resource Groups in Azure using the PowerShell and Azure CLI command-line tools. - [Creating a Resource Group in the Azure portal](https://ulyssesneves.com/2019/07/26/criando-um-resource-group-no-portal-do-azure/): In this post, we introduced the concept and applications of a Resource Group, what tags are, and how to use them with this resource. We showed how to create an empty Resource Group using the Azure portal and during the creation of a new service. - [Microsoft Azure Identity](https://ulyssesneves.com/2019/07/22/microsoft-azure-identity/): In this post, we covered the concept of Microsoft Azure Identity and presented the products that are part of this Azure product category. - [Microsoft 365 Education - Licensing](https://ulyssesneves.com/2019/07/19/microsoft-365-education-licencas/): In this post we talk about the Microsoft 365 Education product. We explain the application areas of this product, the available licenses, and the availability of Microsoft tools for each license. - [Microsoft 365 Business - Licenses](https://ulyssesneves.com/2019/07/16/microsoft-business-licencas/): In this post, we'll talk about the Microsoft 365 Business product, its applications, tools, and licensing options. - [Microsoft 365 Enterprise - Licenses](https://ulyssesneves.com/2019/07/14/microsoft-365-enterprise-licencas/): In today's post, we presented the licenses that make up the Enterprise version of Microsoft 365. We also showed the comparison between the licenses and the products available under each license in this product. - [Microsoft 365 - Introduction](https://ulyssesneves.com/2019/07/11/microsoft-365-introducao/): In this first post, I give an introduction to Microsoft 365 and its products, which is divided into Microsoft 365 Enterprise, Microsoft 365 Business, and Microsoft 365 for Education. - [Hello, everyone!](https://ulyssesneves.com/2019/07/06/ola-mundo/): I decided to create this blog with the goal of sharing experience and knowledge about Microsoft Office 365 and Exchange. We’ll start by covering concepts and tools to help beginners, and we’ll progress with knowledge nuggets on specific features of each one, including troubleshooting. More news is on the way.. [ ]’s Ulysses Related guides: Browse the Microsoft Identity Troubleshooting Index. - [Microsoft Entra SMS and Voice Retirement: An Admin Preparation Checklist](https://ulyssesneves.com/2026/09/24/entra-sms-voice-retirement-admin-checklist/): Prepare for Microsoft Entra SMS and voice retirement with practical checks for authentication methods, passkey registration, and password recovery. - [Microsoft Defender for Identity domain investigation: six questions to ask first](https://ulyssesneves.com/2026/09/10/microsoft-defender-for-identity-domain-investigation-six-questions-to-ask-first/): A six-pass, documentation-based guide to reading Microsoft Defender for Identity Domain investigation: coverage, identities, policies, trusts, recommendations, and evidence. - [Microsoft Entra Kerberos key rotation: what changes—and what administrators should check](https://ulyssesneves.com/2026/09/06/microsoft-entra-kerberos-key-rotation-explained/): Understand Microsoft Entra Kerberos key rotation, the primary-to-secondary key handover, and the June 2026 reliability improvement for incoming trust referral flows. - [Microsoft Authenticator Will Block Jailbroken Devices in 2026 — What You Need to Know](https://ulyssesneves.com/2026/03/17/microsoft-authenticator-will-block-jailbroken-devices-in-2026-what-you-need-to-know/): Starting February 2026, Microsoft Authenticator will introduce jailbreak/root detection for work or school accounts. Microsoft states this change is intended to prevent work or school accounts in Authenticator from functioning on jailbroken or rooted devices. - [Enhancing Azure role activation security with FIDO2/Passkeys](https://ulyssesneves.com/2024/09/23/enhancing-azure-role-activation-security-with-fido2-passkeys/): Configuring Entra Privileged Identity Management (PIM) with Conditional Access authentication context and Conditional Access authentication strength can significantly enhance your organization's security posture. By requiring users to meet specific authentication requirements when activating roles in PIM, you can ensure that sensitive roles are only accessed under the most secure conditions. - [Microsoft Entra ID CAP | Enforcing WHfB using Authentication Strength](https://ulyssesneves.com/2024/04/21/microsoft-entra-id-cap-enforcing-whfb-using-authentication-strength/): Explore Microsoft 365 security as we guide you through implementing a Conditional Access policy that requires Windows Hello for Business authentication. This step-by-step tutorial covers the integration process, authentication strength configuration, and offers insights into expected error messages. Discover how to investigate and resolve issues efficiently, ensuring a seamless transition to this advanced security measure and strengthening your Microsoft 365 environment against unauthorized access. Elevate your digital workspace security and empower users with this comprehensive guide. - [Troubleshooting Error Code '0x000005e' in WHfB: PIN Authentication Woes](https://ulyssesneves.com/2024/02/11/troubleshooting-error-code-0x000005e-in-whfb-pin-authentication-woes/): Encountering error code '0x000005e' during PIN-based authentication in Windows Hello for Business (WHfB) can be a roadblock for users. In this blog post, we'll delve into a specific scenario where users face this issue immediately after the enrollment process in a cloud Kerberos trust scenario. - [WHfB: Fixing Windows Hello for Business error 'LogoncertTemplateReady: NO (StateNoTemplate)'](https://ulyssesneves.com/2023/12/29/whfb-fixing-windows-hello-for-business-error-logoncerttemplateready-no-statenotemplate/): Greetings, readers. In this article, we will delve into the process of investigating and resolving the message "LogoncertTemplateReady: NO (StateNoTemplate)" that may surface during Windows Hello for Business (WHfB) Hybrid Certificate trust deployments. - [Windows Services - Solving common issues that prevent Windows services from starting](https://ulyssesneves.com/2023/09/22/windows-services-solving-common-issues-that-prevent-windows-services-from-starting/): Hello everyone. In this article, I will cover three common issues that prevent Windows services from starting. As an example, we'll use the Print spooler service, but this could be applicable to any service under Windows Services. - [Microsoft Entra Conditional Access – Enforcing passwordless sign-in with Microsoft Authenticator using authentication strengths](https://ulyssesneves.com/2023/07/28/aad-cap-enforcing-passwordless-sign-in-with-ms-authenticator-to-users-using-conditional-access-authentication-strength/): Hello everyone. In this article, I will cover the steps to enforce users to use passwordless sign-in with Microsoft Authenticator with Authentication Strength in Microsoft Entra Conditional Access policy. - [WHfB Cloud Kerberos Trust - Fixing config issue: 'Cloud trust for on-premise auth policy is enabled: No'](https://ulyssesneves.com/2023/06/19/whfb-cloud-kerberos-trust-fixing-config-issue-cloud-trust-for-on-premise-auth-policy-is-enabled-no/): Hello everyone. In this article, I will cover one common issue when moving from WHfB Certificate trust to WHfB Cloud Kerberos Trust. - [WHfB Cloud Kerberos Trust - Windows Hello for Business provisioning will not be launched.](https://ulyssesneves.com/2023/05/22/whfb-cloud-kerberos-trust-windows-hello-for-business-provisioning-will-not-be-launched/): Hello everyone. For the ones implementing Azure AD Cloud Kerberos Trust and the WHfB popup doesn't show up, please check this article. Today, I will share a few interesting logs to investigate WHfB Cloud Kerberos Trust enrollment issues. Normally they are related to missing requirements. - [AD FS - Fixing error message: None of the UPNs were successful for S4U Logon call](https://ulyssesneves.com/2023/04/24/ad-fs-fixing-error-message-none-of-the-upns-were-successful-for-s4u-logon-call/): Hello everyone. Today, we’re going to investigate the error message 'None of the UPNs were successful for S4U Logon call‘ on AD FS servers when users are trying to authenticate from extranet using a Web Application Proxy service. - [AD FS – Fixing error message ‘Your credentials did not work’ when authenticating to a Microsoft Entra joined machine](https://ulyssesneves.com/2023/03/22/ad-fs-fixing-error-message-your-credentials-did-not-work-when-trying-to-authenticate-into-an-aad-joined-machine/): In this article, we covered how to identify and fix the error message 'Your credentials did not work' during a sign-in against one Azure AD Joined machine on a federated Azure AD domain. - [Microsoft Entra ID IPv6 support – Prepare for the change](https://ulyssesneves.com/2023/02/23/azure-ad-ipv6-support-prepare-for-the-change/): Hello everyone. If you have IPv6 implemented in your organization's network and use Azure AD security tools such as location-based conditional access policies, you should consider reading this article. - [Device registration - Fixing error message 'The registration service could not successfully authenticate your account.'](https://ulyssesneves.com/2023/02/13/device-registration-fixing-error-message-the-registration-service-could-not-successfully-authenticate-your-account/): Hello everyone. Today, we’re going to investigate the error message ‘The registration service could not successfully authenticate your account.‘ when trying to Hybrid join domain-joined down-level device into Azure AD. - [AD FS - Fixing error message 'The Web request failed because the web.config is malformed. Access Denied' when establishing AD FS WAP Trust](https://ulyssesneves.com/2023/01/18/ad-fs-fixing-error-message-the-web-request-failed-because-the-web-config-is-malformed-access-denied-when-establishing-ad-fs-wap-trust/): Hi mates. Today we’re going to cover a specific error when establishing trust between Web Application Proxy and AD FS servers: 'The Web request failed because the web.config is malformed. Access Denied'. - [Device registration – Historical guidance: Fixing “wiaormultiauthn is not valid” on down-level Windows](https://ulyssesneves.com/2022/12/14/device-registration-fixing-error-message-the-requested-authentication-method-wiaormultiauthn-is-not-valid/): Hello everyone. Today, we’re going to investigate the error message ‘The requested authentication method 'wiaormultiauthn' is not valid‘ when trying to Hybrid join domain-joined down-level device into Azure AD. - [Microsoft Entra hybrid join – Troubleshooting error code 0x80070005 during the ‘Join’ phase](https://ulyssesneves.com/2022/10/10/azure-ad-hybrid-device-join-troubleshooting-error-code-0x80070005-during-join-phase/): Hello everyone. Today, we’re going to investigate the error message ‘DsrDeviceAutoJoin failed 0x80070005‘ when trying to turn a domain-joined device into Hybrid Azure AD Joined. - [Microsoft Entra hybrid join – Troubleshooting error code 0x801c0021 during the ‘discover’ phase](https://ulyssesneves.com/2022/09/16/azure-ad-hybrid-device-join-troubleshooting-error-code-0x801c0021-during-the-discover-phase/): Hello everyone. Today, we’re going to investigate the error message ‘DsrCmdJoinHelper::Join: TenantInfo::Discover failed with error code 0x801c0021‘ when trying to turn a domain-joined device into Hybrid Azure AD Joined. - [Microsoft Entra hybrid join – Troubleshooting error code 0x8007054b during the pre-check phase](https://ulyssesneves.com/2022/08/16/azure-ad-hybrid-device-join-troubleshooting-error-code-0x8007054b-during-pre-check-phase/): Hello everyone. Today, we’re going to investigate the error message 'No domain controller is available for the specified domain or the domain does not exist: 0x8007054b' when trying to turn a domain-joined device into Hybrid Azure AD Joined. - [WHfB - Fixing error message 0xCAA20064 during windows hello for business certificate trust enrollment](https://ulyssesneves.com/2022/07/28/whfb-fixing-error-message-0xcaa20064-during-windows-hello-for-business-certificate-trust-enrollment/): Hi mates. Today I will cover error message 0xCAA20064 during Windows Hello sign-in certificate enrollment.  - [WHfB - Suppressing Windows Hello for Business provisioning using Group Policy](https://ulyssesneves.com/2022/07/03/whfb-suppressing-windows-hello-for-business-provisioning-using-group-policy/): Hi everyone. Today, we’re going to share a very useful Active directory group policy to help you deploy windows hello for business.  Scenario: By default, once you enable Windows Hello for Business using GPO, once the users affected by the policy sign in, they receive the WHfB enrollment prompt. This rollout can confuse users if not properly communicated by the IT Admins. To help administrators avoid prompting users for WHfB enrollment immediately after sign-in, the option 'Do not start Windows Hello provisioning after sign-in' in the 'Use Windows Hello for Business' policy can be used. - [AD FS - Backing up/restore AD FS configurations into Azure using AD FS Rapid Restore tool](https://ulyssesneves.com/2022/06/15/ad-fs-backing-up-restore-ad-fs-configurations-into-azure-using-ad-fs-rapid-restore-tool/): Hello everyone. Today we’re going to share a method to run AD FS configuration backup and restore using Azure storage and the AD FS Rapid Restore tool. - [Device Registration - Investigating error message: ' DeviceAuthStatus : FAILED. Device is either disabled or deleted'](https://ulyssesneves.com/2022/06/02/device-registration-investigating-error-message-deviceauthstatus-failed-device-is-either-disabled-or-deleted/): Hello everyone. Today we’re going to investigate the message 'DeviceAuthStatus : FAILED. Device is either disabled or deleted' on a Hybrid Joined scenario, which can cause error code 50155 on Azure AD Signing logs. - [The Journey to Password Authentication - What is the Passwordless Authentication?](https://ulyssesneves.com/2022/05/19/the-journey-to-password-authentication-what-is-the-passwordless-authentication/): Hello everyone. Today I want to share with you a Tech Talk session with Kazeem about the Journey to Password Authentication. Summary I hope you have enjoyed the session, and it helps you with passwordless adoption journey. Enjoyed the session? Like and share. 🙂 Note: I do not represent the organization I work for, all the opinions expressed here, are my own. This post is provided AS IS with no warranties or guarantees and confers no rights. In case you have any suggestions or feedback, please leave a comment. [ ]’s Ulysses Neves Related guides: Browse the Microsoft Identity Troubleshooting Index or the Passwordless authentication topic… - [Microsoft Entra hybrid join – Fixing error message error_missing_device](https://ulyssesneves.com/2022/05/03/hybrid-azure-ad-join-fixing-error-message-error_missing_device/): Hello everyone. In this article, I will show how to fix the error message error_missing_device when you try to have your domain-joined device as Hybrid Join with Azure AD as part of this deployment plan available in this Microsoft public document ‘Plan your hybrid Azure Active Directory join implementation‘. Scenario: Device OS: Windows 10GOAL: Have the device achieve the status ‘Hybrid Azure AD Joined’Issue: Automatic-Device-Join task in the Windows Task Scheduler ends with ‘Las Run Result’ (0x1): Investigation: Checking the local event viewer log Microsoft-Windows-User Device Registration/Admin, we see the error message below: The get join response operation callback failed with… - [WHfB - Fixing message 'That option is temporarily unavailable. For now, please use a different method to sign in'](https://ulyssesneves.com/2022/04/15/whfb-fixing-message-that-option-is-temporarily-unavailable-for-now-please-use-a-different-method-to-sign-in/): Hello everyone. Today we’re going to investigate message 'That option is temporarily unavailable. For now, please use a different method to sign in' when a user tries to use recent setup PIN on windows hello for business Hybrid deployments. - [AD FS - Fixing error message 'No client certificate associated with the request was found' when establishing WAP Trust](https://ulyssesneves.com/2022/03/31/ad-fs-fixing-error-message-no-client-certificate-associated-with-the-request-was-found-when-establishing-wap-trust/): Hi everyone. Today we’re going to cover the error message 'No client certificate associated with the request was found.’ during Web Application Proxy trust configuration. - [WHfB: Troubleshooting Windows Hello for Business provisioning AdfsRaIsReady:UNKNOWN](https://ulyssesneves.com/2022/03/15/whfb-troubleshooting-windows-hello-for-business-provisioning-adfsraisreadyunknown/): Hi everyone. Today, we’re going to explain how to investigate and fix the message 'AdfsRaIsReady:UNKNOWN' during Windows Hellos for Business Hybrid Certificate trust deployment. - [WHfB - Fixing error message 'Your credentials could not be verified'](https://ulyssesneves.com/2022/02/27/whfb-fixing-error-message-your-credentials-could-not-be-verified/): Hi everyone. Today, we’re going to investigate the error message 'Your credentials could not be verified' when a user is trying to authenticate using a PIN to authenticate on a Hybrid WHfB deployment. - [AD FS Fixing error message “Error 1069: The service did not start due to logon failure”](https://ulyssesneves.com/2022/02/15/ad-fs-fixing-error-message-error-1069-the-service-did-not-start-due-to-logon-failure/): Hello everyone. Today we are going to cover error message 1069: The service did not start due to logon failure” when you have AD FS farm with WID (Windows Internal Database) service not starting and consequently Active Directory Federation Service does not start either. - [Microsoft Entra ID – Fixing the Download devices feature with a ‘failed’ error message](https://ulyssesneves.com/2022/02/01/azure-ad-fixing-download-devices-feature-with-failed-error-message/): Hello guys. Today I will share some guidance on troubleshooting and fixing the immediate failure once you are trying to use the feature 'Download devices (Preview)' in AAD and receive immediately an error message without many details on it. - [AD FS – Historical guidance: Enabling MFA Server as primary authentication method](https://ulyssesneves.com/2022/01/02/ad-fs-enabling-mfa-server-as-primary-authentication-method-on-ad-fs/): Hi mates. Today we’re going to share how to enable additional authentication method to be used as primary authentication on AD FS. On this article, we'll setup Azure Multi-Factor Authentication Server adapter, but these steps can be applied to Azure MFA adapter or any third-party additional authentication method supported by AD FS. - [AD FS - Phased MFA provider's migration on federated tenant using AD FS 2019 Additional Authentication Policy](https://ulyssesneves.com/2021/12/03/ad-fs-phased-mfa-providers-migration-on-federated-tenant-using-ad-fs-2019-additional-authentication-policy/): Hi mates. Today we’re going to explain how to do a phased migration between additional authentication providers using AD FS authentication policy based on active directory security groups. - [AD FS – Historical MFA Server troubleshooting: “The selected authentication method is not available”](https://ulyssesneves.com/2021/11/16/ad-fs-fixing-error-message-the-selected-authentication-method-is-not-available-when-integrated-with-mfa-server/): Hi mates. Today we’re going to cover the error message 'The selected authentication method is not available' when you have AD FS integrated with MFA Server. - [AD FS - Fixing error message 'The SSL certificate specified by thumbprint does not have a subject name that matches the specified' during WAP trust process](https://ulyssesneves.com/2021/10/29/ad-fs-fixing-error-message-the-ssl-certificate-specified-by-thumbprint-does-not-have-a-subject-name-that-matches-the-specified-during-wap-trust-process/): Hello guys. Today I will share some guidance on troubleshooting and fixing the error message 'The SSL certificate specified by thumbprint 'SSL Thumbprint' does not have a subject name that matches the specified' during a WAP trust configuration. - [AD FS - Changes on AD FS endpoints not replicating on Web Application Proxy servers](https://ulyssesneves.com/2021/10/13/ad-fs-changes-on-ad-fs-endpoints-not-replicating-on-web-application-servers/): Hi mates. Today, I will share with you an expected scenario when we enabled/disable endpoints on AD FS and these endpoints are not updated on Web Application Proxy servers. - [AD FS - Fixing error message 'The system cannot find the file specified' when adding a new AD FS node to the farm](https://ulyssesneves.com/2021/09/28/ad-fs-fixing-error-message-the-system-cannot-find-the-file-specified-when-adding-a-new-ad-fs-node-to-the-farm/): Hi mates. Today we’re going to share how to identify and fix error message 'The system cannot find the file specified' when trying to add a new AD FS server to the farm. - [Cloud Summit 2021](https://ulyssesneves.com/2021/09/20/cloud-summit-2021/): I am happy to be able to deliver one session about Securing Cloud Access with Azure Active Directory today at Cloud Summit 2021. 😍😊 - [Microsoft Entra hybrid join – Fixing error message: Server error: The user certificate is not found on the device with id:](https://ulyssesneves.com/2021/09/07/hybrid-azure-ad-join-fixing-error-message-server-error-the-user-certificate-is-not-found-on-the-device-with-id/): Hi all. Today we are going to cover the error message 'The user certificate is not found on the device with id: device's ID' on Event viewer and the device is with status 'Pending' on Azure AD. - [AD FS - WAP Trust error message System.Security.Cryptography.CryptographicException: Access is denied.](https://ulyssesneves.com/2021/08/21/ad-fs-wap-trust-error-message-system-security-cryptography-cryptographicexception-access-is-denied/): Hi mates. Today we’re going to cover the error message System.Security.Cryptography.CryptographicException: Access is denied when configuring the trust between a Web application Proxy and AD FS servers. - [AD FS - Fixing error message MSIS9605: The client is not allowed to access the requested resource on AD FS 2019](https://ulyssesneves.com/2021/08/03/ad-fs-fixing-error-message-msis9605-the-client-is-not-allowed-to-access-the-requested-resource-on-ad-fs-2019/): Hi mates. Today we’re going to work on the error MSIS9605: The client is not allowed to access the requested resource. on AD FS when a hybrid device tries to get an Enterprise PRT. - [Azure Summit session: Securing Cloud access with Azure Active Directory](https://ulyssesneves.com/2021/07/24/azure-summit-session-securing-cloud-access-with-azure-active-directory/): Hi all. Great news to share on this post! 😊 This year, I will bring a session explaining the Azure AD security tools to protect access to applications hosted in the cloud at #AzureSummit2021. I hope you subscribe below and have fun with my session and all others that will be delivered at this event. Register here>> https://lnkd.in/e4KTDPT Stratis Platform #AzureSummit#Azure#cloud#MicrosoftAzure - [AD FS - Troubleshooting WAP Trust error: ProxyTrustUserName listener error](https://ulyssesneves.com/2021/07/19/ad-fs-troubleshooting-wap-trust-error-proxytrustusername-listener-error/): Hello guys. Today I will cover one error message 'ProxyTrustUserName listener error' you might come across when configuring a new Web Application Server on the AD FS farm. - [AD FS – Deploying AD FS on SQL Server running on a custom port](https://ulyssesneves.com/2021/07/06/ad-fs-deploying-ad-fs-on-sql-server-running-on-a-custom-port/): Hi mates. Today, we’re going to explain how to deploy AD FS farm with SQL Server configured with a custom TCP port using Server Manager wizard and PowerShell. - [AD FS - Troubleshooting WAP Trust error The remote server returned an error: (503) Server Unavailable](https://ulyssesneves.com/2021/06/18/ad-fs-troubleshooting-wap-trust-error-the-remote-server-returned-an-error-503-server-unavailable/): Hi mates. Today we’re going to cover how to investigate and fix WAP Trust error Service Unavailable when AD FS endpoint /adfs/proxy/establishTrust/ is not available. - [AD FS - Troubleshooting Wap trust error The remote server returned an error: (400) Bad Request](https://ulyssesneves.com/2021/05/13/ad-fs-troubleshooting-wap-trust-error-the-remote-server-returned-an-error-400-bad-request/): Hi mates. Today we’re going to cover the error message The remote server returned an error: (400) Bad Request when you are configuring trust between WAP and AD FS server. - [AD FS - Troubleshooting error: The certificate specified does not meet all the requirements of an SSL certificate](https://ulyssesneves.com/2021/05/13/ad-fs-troubleshooting-error-the-certificate-specified-does-not-meet-all-the-requirements-of-an-ssl-certificate/): Hi mates. Today we’re going to explain things to check when you receive the error message: The certificate specified does not meet all the requirements of an SSL certificate during a SSL certificate configuration on AD FS. - [AD FS - Troubleshooting WAP Trust errors (database replication)](https://ulyssesneves.com/2021/04/25/ad-fs-troubleshooting-wap-trust-errors-database-replication/): Hi mates. Today we’re going to cover how to investigate and fix WAP Trust error Service Unavailable when you have more than one AD FS server in the farm configured with WID (Windows Internal Database). - [AD FS - Troubleshooting AD FS event 'web.config file is malformed'](https://ulyssesneves.com/2021/04/03/ad-fs-troubleshooting-ad-fs-event-web-config-file-is-malformed/): Hi mates. Today we’re going to cover a specific error when establishing trust between Web Application Proxy and AD FS backend servers: "The Web request failed because the web.config file is malformed". - [AD FS - Fixing event 543 on AD FS 2019 on mixed mode farm](https://ulyssesneves.com/2021/03/20/ad-fs-fixing-event-543-on-ad-fs-2019-on-mixed-mode-farm/): Hi mates. Today we’re going to explain how to eliminate event 543 on AD FS version 2019 when you have a mixed mode AD FS farm. - [AD FS - Troubleshooting TLS version errors when configuring WAP trust with AD FS](https://ulyssesneves.com/2021/03/06/ad-fs-troubleshooting-tls-version-errors-when-configuring-wap-trust-with-ad-fs/): Hi all. Today I will share with you some steps to help you troubleshoot TLS version mismatch that break the trust between Web Application Proxy and AD FS servers. - [AD FS - Joining a new federation server to an existing AD FS farm using PowerShell](https://ulyssesneves.com/2021/02/21/ad-fs-joining-a-new-federation-server-to-an-existing-ad-fs-farm-using-powershell/): Hi mates. Today we’re going to explain how to add a new federation server to an existing AD FS farm using PowerShell. These steps can be useful in case you want to automate your AD FS farm deployment. - [AD FS - Accessing the certificate store of a gMSA account](https://ulyssesneves.com/2021/02/04/ad-fs-accessing-the-certificate-store-of-a-gmsa-account/): Hi mates. Today we're going to cover how to check Token signing and token decrypting certificates in the certificate store when you have a gMSA (Group Managed Service Accounts) account running AD FS service. AD FS token signing and token decrypting certificates are stored in the certificate store of the service account that runs AD FS. Normally when you want to check the personal certificate store of a service account in AD FS you run the command prompt as another user, but when you have AD FS running with a gMSA account, you have no access to it's password so, here comes a tip to help you check the self-signed token signing and token decrypting certificates in the certificate store. - [AD FS - Migrating ADFS configuration Database from WID to SQL using SSMS](https://ulyssesneves.com/2021/01/22/ad-fs-migrating-adfs-configuration-database-from-wid-to-sql-using-ssms/): Hi all. Today I will share with you the steps to migrate the AD FS configuration database from WID to SQL server using the SQL Server Management Studio (SSMS). - [AD FS - Controlling access to applications using Banned Ip List on AD FS](https://ulyssesneves.com/2021/01/06/ad-fs-controlling-access-to-applications-using-banned-ip-list-on-ad-fs/): Hi guys. Today I will share with you quickly a security feature on AD FS called Banned IP List. It was introduced on Windows Server version 2016 to help admins control access to applications hosted in AD FS based on IP. It can be considered in scenarios where admins want to block IPs that are considered malicious or for any reason should not access Applications integrated to AD FS. - [AD FS - Configuring Extranet Lockout Threshold Familiar Location in AD FS](https://ulyssesneves.com/2020/12/27/ad-fs-configuring-extranet-lockout-threshold-familiar-location-in-ad-fs/): Hi mates. Today I will share with you a parameter introduced in AD FS version 2019 that can help users with wrong passwords when trying to sign in from the extranet. It's called Extranet Lockout Threshold Familiar Location. - [AD FS - Identifying WS-FED and SAML protocols in AD FS with Fiddler](https://ulyssesneves.com/2020/12/13/ad-fs-identifying-ws-fed-and-saml-protocols-in-ad-fs-with-fiddler/): In this article I'll explain what are WS-FED and SAML protocols and how to identify which one is being used with Fiddler. - [AD FS - Configuring Claims Provider Trusts between two AD FS farms](https://ulyssesneves.com/2020/11/20/ad-fs-configuring-claims-provider-trust-between-two-ad-fs-farms/): Hey all. Today, I will show how to configure the claims provider trust between two AD FS farms to allow system admins give access to applications federated to an AD FS farm with users coming from another farm. - [AD FS - Identifying servers running the Web Application Proxy service in the AD FS environment](https://ulyssesneves.com/2020/11/11/ad-fs-identificando-servidores-com-o-servico-web-application-proxy-no-ambiente-ad-fs/): Hello everyone. In today's article I'll quickly explain how to identify which WAP (Web Application Proxy) servers are configured in the AD FS farm using the Certificate Store and also PowerShell. - [Microsoft Entra multifactor authentication - Identifying whether a user is blocked for MFA in Microsoft Entra ID](https://ulyssesneves.com/2020/11/03/azure-mfa-identificando-se-um-usuario-esta-bloqueado-para-mfa-no-azure-ad/): Hello, everyone. In today's article I'll bring a simple tip that can help Microsoft Entra ID support engineers when dealing with users having trouble registering for MFA. - [Microsoft Entra Multifactor Authentication - Populating Phone Information for MFA Using PowerShell and Microsoft Graph](https://ulyssesneves.com/2020/10/20/azure-mfa-preenchendo-as-informacoes-de-telefone-para-mfa-usando-o-poweshell-e-o-microsoft-graph/): Hello everyone. Many administrators face the tough mission of automating tasks to make life easier for the end user. In today's article, we'll explain how to pre-populate MFA information in Azure AD using PowerShell and Microsoft Graph, preventing users from having to complete this registration during the company's MFA rollout. - [AD FS - Updating the SSL and Service Communication Certificates on AD FS](https://ulyssesneves.com/2020/09/30/ad-fs-atualizando-os-certificados-ssl-e-de-comunicacao-de-servico-no-ad-fs/): In today's article, I'll explain how to generate and update the SSL certificate on AD FS using Microsoft Entra Connect and update the service communication certificate using the AD FS console. - [AD FS - Updating the Token-signing and Token-decrypting certificates in AD FS](https://ulyssesneves.com/2020/08/26/ad-fs-atualizando-os-certificados-token-signing-e-token-decrypting-no-ad-fs/): Update notice — September 2026: This article contains commands from the Azure AD or MSOnline PowerShell modules maintained since its original publication. Microsoft has deprecated these modules and recommends Microsoft Graph PowerShell for current automations. Do not use the legacy commands in new implementations. Source: Guidance for migrating to Microsoft Graph: “Azure AD, Azure AD Preview and MSOnline PowerShell modules are deprecated.” Hello everyone. Are you one of those administrators who shudders just seeing that the time is coming to update the AD FS certificates? 😱 In today’s article I’ll explain how to update the AD FS Token-signing and Token-decrypting certificates… - [AD FS - Protecting users with AD FS Extranet Smart Lockout](https://ulyssesneves.com/2020/08/07/ad-fs-protegendo-usuarios-com-o-ad-fs-extranet-smart-lockout/): Hello everyone. In today's article I'll cover a very interesting AD FS feature that helps protect domain accounts from attacks such as "password spray" using AD FS Extranet lockout. This feature is called AD FS Extranet Smart Lockout. - [AD FS - How to Configure JEA (Just Enough Administration) with AD FS](https://ulyssesneves.com/2020/07/28/ad-fs-como-configurar-o-jea-administracao-suficiente-com-ad-fs/): Hello everyone. In today's article, I'll explain how to configure JEA (Just Enough Administration) in the AD FS service. This feature allows AD FS service administrators to delegate limited access to other users without the need to grant administrative access to the servers. One example is delegating to user support technicians permission to unlock accounts locked by AD FS Smart lockout. - [Microsoft Entra ID - Controlling Unknown Devices Using Conditional Access Policy in Microsoft Entra ID](https://ulyssesneves.com/2020/07/14/azure-ad-controlando-dispositivos-desconhecidos-usando-politica-de-acesso-condicional-no-azure-ad/): Hello everyone. When configuring a conditional access policy based on platform (operating system), it can happen that the administrator doesn't account for operating systems that aren't listed in the policy — for example, unsupported platforms, or cases where client applications don't send device information during authentication. The result is that this access isn't controlled by the Azure policy. - [Azure App Services - Publishing an application with a custom domain and SSL on Azure](https://ulyssesneves.com/2020/07/04/azure-app-services-publicando-uma-aplicacao-com-dominio-personalizado-e-ssl-no-azure/): Hello everyone. In today's article I'll explain step by step how to create an app service on Azure, configure the application on a custom domain, and enable SSL for secure access. - [Microsoft Entra ID - How to limit access to Outlook Web Access data using a CA policy](https://ulyssesneves.com/2020/06/22/azure-ad-como-limitar-o-acesso-aos-dados-do-outlook-web-access-usando-ca-policy/): Hello everyone. Today I'll present a step-by-step guide on how to integrate Conditional Access policies with Exchange Online policies to limit access to OWA. With the rise of mobility and the growing concern organizations have about protecting information stored on mobile devices, administrators face the difficult task of protecting the information that users can access. - [Microsoft Entra ID - Enabling SMS-based authentication](https://ulyssesneves.com/2020/06/11/azure-ad-habilitando-a-autenticacao-baseada-em-sms/): Hello everyone. In today's article we'll show how to enable the option for accessing applications hosted or integrated with Microsoft Entra ID using SMS-based authentication. - [Microsoft Entra ID - How to emulate an Android device with Android Studio](https://ulyssesneves.com/2020/05/28/azure-ad-como-emular-um-dispositivo-android-com-o-android-studio/): Hello everyone. It is common for Microsoft Entra ID administrators to run into the need to analyze an access problem to applications in Azure via mobile devices, or to need to validate a user's behavior on different device versions. To help these administrators, I decided to explain in today's article how to emulate an Android device using the Android Studio software. - [Microsoft Entra application proxy – Historical connector installation and current prerequisites](https://ulyssesneves.com/2020/05/18/azure-ad-instalando-o-app-proxy-connector/): Hello everyone. In today's article, I'll show you how to install the App Proxy connector on a Windows server and how to validate its registration in Microsoft Entra ID. - [AD FS - Monitoring AD FS with the Microsoft Entra Connect Health Agent for AD FS](https://ulyssesneves.com/2020/05/08/ad-fs-monitorando-o-ad-fs-com-o-azure-ad-connect-health-agent-for-ad-fs/): Hello everyone. In today's article we'll show you how to install the Microsoft Entra Connect Health Agent for AD FS and monitor the environment through the Azure portal. - [AD FS - Controlling Access to the Azure Portal Using AD FS Access Policies](https://ulyssesneves.com/2020/04/27/ad-fs-controlando-o-acesso-ao-portal-do-azure-utilizando-politicas-de-acesso-no-ad-fs/): Hello everyone. In today's article, we'll demonstrate how to restrict access to Azure AD resources using AD FS access control rules for domains federated with Azure AD. With AD FS access control rules, you can control internal and external access to an RPT (relying party trust) using location, device status, or even access containing a specific attribute. - [Microsoft Entra Conditional Access Policy - Controlling browsing sessions using Conditional Access policies](https://ulyssesneves.com/2020/04/17/azure-ca-policy-controlando-sessoes-de-navegacao-usando-politicas-de-acesso-condicional/): Hi everyone. In today's article, we'll introduce the browser session management option available in Microsoft Entra Conditional Access policy. - [AD FS - Integrating Microsoft Entra Multifactor Authentication with AD FS](https://ulyssesneves.com/2020/04/08/ad-fs-integrando-o-azure-mfa-ao-ad-fs/): Hello, everyone. In today's article, we'll show how to integrate Microsoft Entra multifactor authentication with AD FS to allow users to use passcodes generated by Microsoft Authenticator when accessing an application. - [AD FS - Enabling the user password update portal in AD FS](https://ulyssesneves.com/2020/03/29/ad-fs-ativando-o-portal-de-atualizacao-de-senha-de-usuario-no-ad-fs/): Hi everyone. In today's article, we'll demonstrate how to enable the user password change option via AD FS. This feature is used when it's necessary to allow users inside or outside the company to update their domain passwords without needing to be connected to the office network. - [AD FS - Customizing the AD FS authentication portal](https://ulyssesneves.com/2020/03/19/ad-fs-personalizando-o-portal-de-autenticacao-do-ad-fs/): Hello everyone. For those who work with AD FS (Active Directory Federation Services), we are starting a series of articles with tips and tutorials related to this service. In today's article, we will show how to make some customizations to the authentication portal. - [Microsoft Entra Conditional Access – Configuring Microsoft 365 using a Conditional Access policy](https://ulyssesneves.com/2020/03/10/azure-ad-configurando-o-office-365-preview-usando-politica-de-acesso-condicional/): Hello, everyone. In today's article, we'll explain what the Office 365 (Preview) application group is and how to use this new feature to control access to Office 365 resources in Azure using a conditional access policy. This configuration is typically used when the administrator wants to block all Office 365 applications except access to email. - [Microsoft Entra ID – Listing Contacts for User Authentication in Entra ID using PowerShell](https://ulyssesneves.com/2020/03/03/azure-ad-listando-contatos-para-autenticacao-de-usuarios-no-azure-usando-powershell/): Olá pessoal. O artigo de hoje mostraremos como listar as informações de contato para autenticação de todos os usuários do Azure AD usando o powershell. Esse artigo surgiu da necessidade de identificar qual usuário possuía o contato de um dispositivo móvel corporativo que recebia códigos de verificação sem que fosse solicitado. - [Microsoft Entra ID - Integrating Microsoft Entra ID identities for access to Azure SQL](https://ulyssesneves.com/2020/02/25/azure-ad-integrando-identidades-do-azure-ad-para-acesso-ao-azure-sql/): Hello, everyone. In today's article, we'll explain step by step how to configure Microsoft Entra ID accounts to access a SQL database in Azure. The integration between Microsoft Entra ID and SQL database instances allows for centralization and greater access control over SQL resources hosted in Azure. It's possible to use credentials replicated to Azure through Microsoft Entra Connect (hybrid) or created directly in Microsoft Entra ID (Microsoft Entra ID-only). - [Azure VM - Integrating Windows Server 2019 Access with Microsoft Entra ID Authentication](https://ulyssesneves.com/2020/02/18/azure-vm-integrando-o-acesso-ao-windows-server-2019-com-autenticacao-no-azure-ad/): Hello everyone. In today's article, we'll show you how to configure an Azure credential to access Windows Server 2019 Datacenter edition or Windows 10 version 1809 or later virtual machines. This functionality is possible because the virtual machine is joined to Microsoft Entra ID during the creation process. - [Microsoft Entra ID - Controlling Access to Azure Through Terms of Use](https://ulyssesneves.com/2020/02/11/azure-ad-controlando-o-acesso-ao-azure-atraves-dos-termos-de-uso/): Hello, everyone. In today's article, we'll explain how to force device registration in Azure using terms of use. This control applies to scenarios where administrators want to identify the devices used by users to access applications hosted in Azure. - [Microsoft Entra ID - Blocking external access to Dynamics 365 using conditional access policy](https://ulyssesneves.com/2020/02/04/azure-ad-bloqueando-o-acesso-externo-ao-dynamics-365-usando-conditional-access-policy/): Hello, everyone. In today's article, we'll explain step by step how to block access to Dynamics applications by location using a conditional access policy. This scenario is quite common in organizations that want to allow access to applications only through trusted networks. - [Azure passwordless - Enabling access to Azure without using passwords](https://ulyssesneves.com/2020/01/28/azure-passwordless-habilitando-o-acesso-ao-azure-sem-o-uso-de-senhas/): Hello, everyone. In today's article, we will explain how to enable access to Azure resources through the Microsoft Authenticator app without using a password. - [Microsoft Entra multifactor authentication - Controlling guest user access in Azure](https://ulyssesneves.com/2020/01/21/azure-mfa-controlando-o-acesso-de-usuarios-convidados-no-azure/): Hello, everyone. In today's article, we'll explain how to configure a conditional access policy for guest users in Azure. Administrators typically require strong authentication methods to be used by users external to the organization to access Azure resources. - [Microsoft Entra ID - Enabling the MFA registration policy using Microsoft Entra ID Identity Protection](https://ulyssesneves.com/2020/01/14/azure-ad-habilitando-a-politica-de-registro-mfa-usando-o-azure-ad-identity-protection/): Hi everyone. In today's article, we'll explain what the MFA registration policy in Azure is and how to configure it using Microsoft Entra ID Identity Protection - [Microsoft Entra ID - Controlling security info registration using Conditional Access Policy](https://ulyssesneves.com/2020/01/07/azure-ad-controlando-o-registro-de-informacoes-de-seguranca-usando-conditional-access-policy/): Hi everyone. In today's article, we'll explain step by step how to restrict access to and updates of security info using a Conditional Access policy. Through the Security Info menu in the user's profile in Azure, it's possible to add or modify the access methods used for authentication in Azure. - [Microsoft Entra ID + 3rd-Party MFA - Configuring MFA with DUO](https://ulyssesneves.com/2020/01/01/azure-ad-3rd-party-mfa-configurando-mfa-com-o-duo/): Hello, everyone. In today's article, we'll explain how to configure an access policy using custom controls with DUO. - [Microsoft Entra ID Devices - Joining a Windows 10 Device as Microsoft Entra Hybrid Joined](https://ulyssesneves.com/2019/12/26/azure-ad-devices-ingressando-um-dispositivo-windows-10-no-ad-hibrido/): Hello, everyone. In today's article, we'll explain step by step how to configure a federated environment with AD FS so that devices joined to the local domain are automatically joined to Microsoft Entra ID. - [Microsoft Entra ID Devices - Manually joining a Windows 10 device to Microsoft Entra ID](https://ulyssesneves.com/2019/12/17/azure-ad-devices-ingressando-manualmente-um-dispositivo-windows-10-no-azure-ad/): Hi everyone. In today's article, we'll explain step by step how to join a Windows 10 device to Microsoft Entra ID. This scenario is used when the company has a cloud-first culture or doesn't have an on-premises domain infrastructure. - [Microsoft Entra ID Devices - Manually Registering a Windows 10 Device in Microsoft Entra ID](https://ulyssesneves.com/2019/12/10/azure-ad-devices-registrando-manualmente-um-dispositivo-windows-10-no-azure-ad/): Hello, everyone. In today's article, we'll walk you through step by step how to manually register a device in Microsoft Entra ID. As covered in the previous topic, device registration in Microsoft Entra ID benefits BYOD scenarios - Bring Your Own Device - and mobile devices, such as smartphones, tablets, etc. - [Microsoft Entra ID Devices - Introduction to Device Management in Microsoft Entra ID](https://ulyssesneves.com/2019/12/03/azure-ad-devices-introducao-ao-gerenciamento-de-dispositivos-no-azure-ad/): In today's article, we'll talk about device management in Azure AD. We'll cover the concepts and requirements for the ways a personal or corporate device can be associated with Azure AD. - [Microsoft Entra multifactor authentication - Configuring MFA usage exception by named location](https://ulyssesneves.com/2019/11/26/azure-mfa-configurando-excecao-de-uso-do-mfa-por-localidade-nomeada/): In today's article, we talked about how to configure an MFA request exception using a conditional access policy and a named location. We showed step by step how to define a policy to exclude a named location as a condition to enforce the use of multi-factor authentication. - [Microsoft Entra multifactor authentication - How to enable MFA using a conditional access policy](https://ulyssesneves.com/2019/11/20/azure-mfa-como-habilitar-o-mfa-usando-politica-de-acesso-condicional/): In today's article, we'll explain how to enable MFA for Azure users using a conditional access policy. This article covers the “configure multi-factor authentication settings” topic of the AZ-500 – Microsoft Azure Security Technologies exam. - [Microsoft Entra multifactor authentication – Assigning licenses to users in Azure for MFA use](https://ulyssesneves.com/2019/11/11/azure-mfa-atribuindo-licencas-a-usuarios-no-azure/): In today's article, we'll show how to assign an MFA license to Azure users using the portal and PowerShell. This article covers the “configure multi-factor authentication settings” topic of the AZ-500 – Microsoft Azure Security Technologies exam. - [Microsoft Entra multifactor authentication – Historical per-user MFA configuration](https://ulyssesneves.com/2019/11/04/azure-mfa-ativando-o-mfa-em-usuarios-no-azure/): In today's article, we'll show how to enable MFA for users in Azure. This article continues covering content from the “configure multi-factor authentication settings” topic of the AZ-500 – Microsoft Azure Security Technologies exam. - [Microsoft Entra Multifactor Authentication - Service Configuration](https://ulyssesneves.com/2019/10/29/azure-mfa-configuracoes-do-servico/): In today's article, we'll enable MFA for users using different methods to show how each one works. This article covers the “configure multi-factor authentication settings” topic of the AZ-500 – Microsoft Azure Security Technologies exam. - [Microsoft Entra multifactor authentication - Introduction to Multi-factor Authentication](https://ulyssesneves.com/2019/10/21/azure-mfa-introducao-ao-multi-factor-authentication/): Hello, everyone. In today's article, we'll explain what Microsoft Entra multifactor authentication is and what it is used for. This article covers the subtopic “configure multi-factor authentication settings” of the AZ-500 – Microsoft Azure Security Technologies exam. ## Pages - [Microsoft Identity Troubleshooting Index](https://ulyssesneves.com/identity-troubleshooting-index/): Use this index to find Microsoft identity deployment and troubleshooting guidance by product, scenario, error code, or message. Articles marked as historical contain prominent notices and links to current Microsoft documentation. Error codes and troubleshooting messages Troubleshooting Error Code '0x000005e' in WHfB: PIN Authentication Woes (2024) WHfB: Fixing Windows Hello for Business error 'LogoncertTemplateReady: NO (StateNoTemplate)' (2023) WHfB Cloud Kerberos Trust – Fixing config issue: 'Cloud trust for on-premise auth policy is enabled: No' (2023) WHfB Cloud Kerberos Trust – Windows Hello for Business provisioning will not be launched. (2023) AD FS – Fixing error message: None of the UPNs were… - [Política de Cookies (UE)](https://ulyssesneves.com/politica-de-cookies-ue/) - [About me...](https://ulyssesneves.com/aboutme/): Thank you for visiting my blog. Learning is every day. This has never been so true for me since I started up on this road of technology. So I consider myself passionate about innovation and how it can be applied to change people’s lives. I’ve been working with technology since 2010. And after discovering this passion, I kept doing my best to improve my technical skills. Always looking forward to learning something every day and finding new ways to leverage digital transformation to the next level. 🚀 Technology brings simplicity and speed to our lives. But what I consider the most… - [Contact](https://ulyssesneves.com/contato/): Follow channels below and provide feedback: Blog: https://ulyssesneves.com Facebook: https://www.facebook.com/blogdoulyssesneves Twitter: https://twitter.com/DasUlysses [ ]’s, Ulysses Neves ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/ulyssesneves.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)