AD FS Metadata Endpoint Synchronization Outage

Scott Lee 0 Reputation points
2026-10-05T16:06:34.15+00:00

Relying party trust fails after AD FS server metadata endpoint becomes unreachable over port 443. How do we update trust metadata manually?

Windows for business | Windows 365 Enterprise
0 comments No comments

2 answers

Sort by: Most helpful
  1. Hoang Le Huy 80 Reputation points Independent Advisor
    2026-10-05T16:42:25.6366667+00:00

    Hello Scott Lee,

    If the federation metadata endpoint is no longer reachable over HTTPS/443, AD FS cannot automatically refresh the relying party trust metadata. In that situation, obtain the latest federation metadata XML file directly from the partner application owner and copy it locally to the AD FS server. Microsoft's supported method is to manually update the trust by running Update-AdfsRelyingPartyTrust -TargetName "<RelyingPartyTrustName>" -MetadataFile "C:\Temp\federationmetadata.xml", which refreshes endpoints, claim settings, and signing certificates from the supplied metadata file.

    If the metadata file cannot be obtained, manually verify and update the relying party's signing certificates, endpoints, and identifiers in AD FS Management > Trust Relationships > Relying Party Trusts > Properties, ensuring any expired signing certificates are removed and replaced with the current ones. Certificate trust and validity must also be verified, as AD FS authentication will fail if token-signing certificates are expired, untrusted, or incorrectly configured.

    If my answer is useful for you, please hit Accept the answer for me please.

    HL.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-10-05T16:06:45.8266667+00:00

    If the relying party trust cannot refresh metadata over port 443, update it manually from federation metadata.

    1. On the AD FS server, export or obtain the current federation metadata XML from the partner.
    2. Run Update-AdfsRelyingPartyTrust against the affected relying party trust and supply the metadata file.

    Examples:

    Update-AdfsRelyingPartyTrust -TargetName "<RelyingPartyName>" -MetadataFile "C:\Path\FederationMetadata.xml"
    

    or

    Update-AdfsRelyingPartyTrust -TargetIdentifier "<RelyingPartyIdentifier>" -MetadataFile "C:\Path\FederationMetadata.xml"
    

    This cmdlet updates claims, endpoints, and certificates from the metadata.

    If the issue is with the Microsoft Entra ID relying party trust specifically, the documented remediation is to update the new certificate thumbprint and the relying party trust date with Microsoft Entra ID.

    If the federation metadata endpoint on the AD FS side is disabled, re-enable it on the primary AD FS server:

    1. Open AD FS 2.0 Management Console.
    2. Go to AD FS (2.0) > Service > Endpoints.
    3. Right-click /Federation Metadata/2007-06/FederationMetadata.xml.
    4. Enable Enable and Enable on Proxy.

    If certificate access is part of the outage, verify the AD FS service account has Read permission to the private key of all configured certificates. Missing access can cause certificate-related trust failures.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.