ADFS – MSIS7012 and MSIS8006 errors

Issue symptom

Some of the federated users are not able to sign in Office 365 portal. In ADFS Admin logs see EventID 111 and 364 with following error message:

Protocol Name:

Relying Party:

Exception details:
Microsoft.IdentityServer.RequestFailedException: MSIS7012: An error occurred while processing the request. Contact your administrator for details. —> Microsoft.IdentityServer.Service.SecurityTokenService.ADAccountValidationException: MSIS8006: Query on Active Directory Account for identity ‘XXX’ returned empty attribute values.

There might be two possible root causes of the issue (those I know about so far 😊 ).

1.      On premises Active Directory User object or OU the user object is located at has ACL preventing ADFS service account reading the User objects attributes (most likely the List Object permissions are missing).

2.      There is an issue with Domain Controllers replication.

For the first one, understand the scope of the effected users, try moving user object to not effected OU and see if the sign in is successful. Compare OU ACLs for working and not working OUs and add missing permissions.

For the second one, start with this article – How To Diagnose Active Directory Replication Failures-

Leave a Reply

Please log in using one of these methods to post your comment: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s