Windows 10 Hybrid Join Automatic registration failed

MJ 21 Reputation points
2021-02-08T06:52:00.347+00:00

Hello,

I am having troubles to let Windows 10 Hybrid Join on startup. It is only working right now when the computer object is synchronised. Because the Windows 10 is a non-persistent VDI it needs to join on startup. I am getting the below error. The ADFS server is in a remote domain with a external domain trust. The SCP is in place and the Endpoints in ADFS are also enabled. Windows Authentication is enabled on the ADFS Intranet. Because it is a multidomain ADFS i was not able to let AD Connect configure it ( https://video2.skills-academy.com/en-us/azure/active-directory/devices/hybrid-azuread-join-federated-domains ). I must be missing something.

Automatic registration failed at authentication phase. Unable to acquire access token.
Exit code: Unknown HResult Error code: 0xcaa9002c
Tenant Name: MY valided Domain
Tenant Type: Federated
Server error:
AdalErrorCode: 0xcaa1000e
AdalCorrelationId: a4c3289b-06ba-40ba-9ee6-ddfef7681f5a
AdalLog: HRESULT: 0xcaa1000e
ADALUseWindowsAuthenticationTenant failed, unable to preform integrated auth
AdalLog: HRESULT: 0xcaa9002c
AdalLog: HRESULT: 0xcaa9002c
AdalLog: HRESULT: 0xcaa9002c
AdalLog: HRESULT: 0x4aa90010
AdalLog: AggregatedTokenRequest::GetAppliesTo: using resource ID "urn:federation:MicrosoftOnline" for authority "https://login.microsoftonline.com/common". ; HRESULT: 0x0
AdalLog: AggregatedTokenRequest::UseWindowsIntegratedAuth- received realm info ; HRESULT: 0x0
AdalLog: HRESULT: 0x4aa90010
AdalLog: AggregatedTokenRequest::UseWindowsIntegratedAuth w Tenant ; HRESULT: 0x0
AdalLog: AggregatedTokenRequest::AcquireToken- returns false ; HRESULT: 0x0
AdalLog: AggregatedTokenRequest::AcquireToken- refresh token is not available ; HRESULT: 0x0
AdalLog: AggregatedTokenRequest::AcquireToken get refresh token info ; HRESULT: 0x0
AdalLog: Authority validation is completed ; HRESULT: 0x0
AdalLog: Authority validation is enabled ; HRESULT: 0x0
AdalLog: Token is not available in the cache ; HRESULT: 0x0

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,259 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.