{"id":23152,"date":"2022-01-25T00:10:00","date_gmt":"2022-01-24T23:10:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=23152"},"modified":"2022-01-24T19:36:48","modified_gmt":"2022-01-24T18:36:48","slug":"windows-january-2022-updates-bricks-active-directory-federation-services","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/01\/25\/windows-january-2022-updates-bricks-active-directory-federation-services\/","title":{"rendered":"Windows January 2022 updates bricks Active Directory Federation Services"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Windows\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" width=\"200\" align=\"left\">[German]It seems, that the January 2022 security updates like KB5009557 bricks Active Directory Federation Services ADFS-Farm-Servers. I receive a report, where update KB5009557 breaks LDAP queries to domain controllers from a ADFS Farm Server. Here are a few details about that issue.<\/p>\n<p><!--more--><\/p>\n<p>I received the following <a href=\"https:\/\/www.borncity.com\/blog\/2022\/01\/12\/windows-server-januar-2022-sicherheitsupdates-verursachen-boot-schleife\/#comment-121014\" target=\"_blank\" rel=\"noopener\">comment<\/a> within my German blog, regarding update KB5009557. Blog reader Phil wrote:<\/p>\n<blockquote>\n<p>ADFS problem<br \/>Hello all.<br \/>I have the following problem after installing KB5009557 on an ADFS farm server.<br \/>The ADFS farm server could no longer make LDAP queries to a DC in another forest (one-way trust).<br \/>EventID 325<br \/>Microsoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity Domain\\User for relying party trust example.com. -&gt; Microsoft.IdentityServer.ClaimsPolicy.Language.PolicyEvaluationException: POLICY0018: Query 'SAMAccountName={0};Attribute_X' to attribute store 'examle.local' failed: 'The supplied credential is invalid.<\/p>\n<p>After uninstalling the patch, it worked again.<\/p>\n<p>The patch was not installed on any DC, only on an ADFS farm server.<\/p>\n<\/blockquote>\n<p>Perhaps it's helpful for administrators affected by the same issue. <\/p>\n<p><strong>Similar articles:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/2022\/01\/05\/windows-server-notfall-update-fixt-remote-desktop-probleme-4-1-2022\/\">Windows Server: Out-of-Band Update fixes Remote Desktop issues (2022\/01\/04)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/05\/microsoft-office-updates-4-januar-2022\/\">Microsoft Office Updates (January 4, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/11\/microsoft-security-update-summary-11-januar-2022\/\">Microsoft Security Update Summary (January 11, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/patchday-windows-8-1-server-2012-r2-updates-11-januar-2022-mgliche-boot-probleme\/\">Patchday: Windows 8.1\/Server 2012 R2 Updates (January 11, 2022), boot loop reported<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/patchday-windows-10-updates-11-januar-2022\/\">Patchday: Windows 10 Updates (January 11, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/patchday-windows-11-updates-11-januar-2022\/\">Patchday: Windows 11 Updates (January 11, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/patchday-updates-fr-windows-7-server-2008-r2-11-januar-2022\/\">Patchday: Updates for Windows 7\/Server 2008 R2 (January 11, 2022)<\/a> <\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/windows-server-januar-2022-sicherheitsupdates-verursachen-boot-schleife\/\">Windows Server: January 2022 security updates are causing DC boot loop<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/windows-vpn-verbindungen-l2tp-over-ipsec-nach-januar-2022-update-kaputt\/\">Windows VPN connections (L2TP over IPSEC) broken after January 2022 update<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/12\/windows-server-2012-r2-januar-2022-update-kb5009586-brickt-hyper-v-host\/\">Windows Server 2012\/R2: January 2022 Update KB5009586 bricks Hyper-V Host<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/14\/microsoft-patch-day-issues-jan-2022-bugs-confirmed-but-updates-not-pulled\/\">Microsoft patch day issues Jan. 2022: bugs confirmed, but updates not pulled<\/a> <\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2022\/01\/17\/microsoft-januar-2022-patchday-revisionen-14-1-2022\/\">Microsoft Microsoft Januar 2022 Patchday Revisions (2022\/01\/14)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/18\/windows-out-of-band-updates-fixes-jan-2020-patch-day-issues-jan-17-2022\/\">Windows Out-of-band Updates fixes Jan. 2022 patch day issues (Jan. 17, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/18\/windows-10-server-out-of-band-updates-fixes-jan-2022-patch-day-issues-jan-17-2022\/\">Windows 10\/Server: Out-of-band Updates fixes Jan. 2022 patch day issues (Jan. 17, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/19\/sonderupdate-fr-windows-server-2019-fixt-jan-2022-patchday-probleme-18-1-2022\/\">Out-of-band Updates for Windows Server 2019 fixes Jan. 2022 Patch day issues (Jan. 18, 2022)<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/19\/windows-7-8-1-server-2008r2-2012r2-out-of-band-updates-with-fixes-for-jan-2022-patch-day-issues-2022-01-17\/\">Windows 7\/8.1; Server 2008R2\/2012R2: Out-of-band Updates with Fixes for Jan. 2022 Patch day Issues (2022\/01\/17)<\/a> <\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2022\/01\/20\/nachlese-fix-fr-windows-ipsec-vpn-verbindungproblem\/\">Review: Fix for Windows IPSec VPN Connection Issues<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/20\/sonderupdate-fr-windows-17-18-jan-2022-fixen-refs-probleme-nur-teilweise\/\">Out-of-Band Updates for Windows (Jan. 17\/18, 2022) doesn't fixes ReFS Issues complete<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2022\/01\/22\/nachlese-fix-fr-hyper-v-host-start-problem-in-windows-januar-2022\/\">Review: Fix for Hyper-V Host Startup Problem in Windows (January 2022)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]It seems, that the January 2022 security updates like KB5009557 bricks Active Directory Federation Services ADFS-Farm-Servers. I receive a report, where update KB5009557 breaks LDAP queries to domain controllers from a ADFS Farm Server. Here are a few details about &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/01\/25\/windows-january-2022-updates-bricks-active-directory-federation-services\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,2],"tags":[47,195,194],"class_list":["post-23152","post","type-post","status-publish","format-standard","hentry","category-issue","category-windows","tag-issue","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=23152"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/23152\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=23152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=23152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=23152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}