Consider the following scenario:
- You have an Active Directory Federation Services (AD FS) passive endpoint that is running Windows Server 2012 R2.
- You enable the ExtendedProtectionTokenCheck setting in an AD FS 3.0 configuration.