Consider the following scenario:
In this scenario, the Active Directory user cannot authenticate with ADFS, and the exception Microsoft.IdentityServer.Service.AccountPolicy.ADAccountLookupException is thrown.
- You have a Windows Server 2012 R2 Active Directory Federation Services (ADFS) server and multiple Active Directory domain controllers.
- This ADFS server has the EnableExtranetLockout property set to TRUE.
- An Active Directory user is created on a replica of a domain controller, and the user has never tried to log in with a bad password.
In this scenario, the Active Directory user cannot authenticate with ADFS, and the exception Microsoft.IdentityServer.Service.AccountPolicy.ADAccountLookupException is thrown.