Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unable to run MMC with local admin; no System.db file #182

Closed
ns3c opened this issue Jun 8, 2021 · 2 comments
Closed

Unable to run MMC with local admin; no System.db file #182

ns3c opened this issue Jun 8, 2021 · 2 comments
Labels

Comments

@ns3c
Copy link

ns3c commented Jun 8, 2021

Hey team,

I'm trying to install adfsmfa from the provided binary on Github.

I've gotten the response "Must be executed with ADFS Administration rights granted for the current user!"

I understand that the account must be a member of the local administrators group (it is, I have confirmed this, added additional users and tested, and relogged / restarted the server to make sure my user session has reset. I also understand the account can be a member of the Delegated Admins Group for ADFS; it is not, and I'm happy to test this as well. We didn't define a group for this in ADFS - would you happen to know the default?

When attempting to follow #167 and delete my system.db files, this does not work. Restarting the service doesn't create a system.db file; this file is only created when I try to open the MMC, which fails with the error, then creates the system.db file.

I was able to execute commands such as Register-MFASystem, but cannot use things like Get-MFAFarmInformation or open the MMC.

Any thoughts on how I can fix this permissions issue? My account does have local administrator, and we'd like to understand root cause if possible so we can use and support this internally.

@redhook62 redhook62 added the bug label Jun 9, 2021
@redhook62
Copy link
Member

HI @ns3c

Indeed, this is a bug.
This happens when the ADFS adminstration group is not populated. Local administrators receive this error.
In the meantime, you can assign an AD group to ADFS administrators.
Wait a bit, we will provide a fix quickly.

regards

@redhook62
Copy link
Member

Hi @ns3c

New version 3.1.2106.2

regards

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants