Troubleshooting CRM for Tablets Login Issues with ADFS

Troubleshooting CRM for Tablets Login Issues with ADFS

All CRM 2013 and CRM Online customers have access to the CRM for Tablets app that’s available for Windows 8, iOS and Android devices. Since it’s an app from the new age of mobile computing, the users can simply download it from the respective app store of the platform provider and install it. Configuring the app to connect with your CRM organization can however prove to be a bit trickier task than this.

If you’re using CRM Online hosted by Microsoft in their data centers, connecting the tablet app to the CRM server in the cloud is usually a straightforward process. Just enter the URL for your organization, then punch in the credentials and off you go. Well, to be more precise, upon your first connection the organization you’ll be taken to a screen that asks you to hold on tight while the app is being set up. This is because all of the metadata related to your CRM organization’s customizations first needs to be loaded, so that you’ll see your own CRM instead of some generic, hard coded menus and fields. This step can take quite a while to finish, but just hold on tight, it’s worth it.

If you’ve got your own on-premises CRM server or you’re logging to CRM Online via your on-premises Active Directory credentials, you may need to work a bit harder to achieve connectivity between the CRM for Tablets app and the CRM server. This is because in both of these scenarios you will have ADFS (Active Directory Federation Services) sitting there in the middle, processing your login request and validating your user credentials. Of course the same technology is also used behind the pure cloud CRM Online service, but MS has done the configuration work for you, whereas with on-premises components you’ll be in charge of performing this.


Recently I was faced with a situation where a customer had deployed Dynamics CRM 2013 SP1 on-premises and done the Internet Facing Deployment via Windows Server 2008 R2 ADFS 2.0, published via Forefront TMG (Threat Management Gateway) 2010. Accessing CRM via the web client through the IFD address was working as expected, so was the CRM Outlook client. CRM for Phones was connecting without issues and I could even connect to the server via tools like XrmToolBox with no issues. There was just one problem: the CRM for Tablets wouldn’t connect to the server, no matter what. In the process of troubleshooting this particular scenario I learned a thing or two about the tablet app connectivity as well as server configuration tasks, so I thought I’d share my findings here on my blog. I’m by no means an expert on anything surrounding ADFS , but I’m stubborn enough to keep searching for answers until I find some from the great wide web.

RTFM – Read The Friendly Manual(s)

First of all, you’ll need to know your ADFS version, since there’s a few new hoops you’ll need to jump through when working with Windows Server 2012 R2 and the latest ADFS 2.2 (sometimes referred to as ADFS 3.0, since official version numbers seem to have been dropped by MS, in favor of just shipping ADFS together with Windows Server releases). The architecture of ADFS has changed considerably from earlier 2.0 and 2.1 versions, with no more IIS in the background, so the configuration process for CRM IFD also differs from the previous experience.

You’ll find the extra steps listed on this article: Configure Windows Server 2012 R2 for CRM mobile clients. On the ADFS 2.2 server you’ll need to enable forms authentication manually, since it’s not enabled by default, like in previous versions. Then you need to run a Powershell script on the CRM server to configure the OAuth provider. Finally, you should register the CRM for Tablets app ID’s with the ADFS server via another Powershell script.

Tablet_AD_login_promptYou may run into an issue with the login process where the user is prompted for their AD credentials via the standard Windows domain dialog window repeatedly. This is because of some incorrect authentication settings that apparently are caused by the CRM IFD configuration process itself. To avoid these issues, you should run a repair installation on the CRM 2013 server with the Web Application Server role deployed, after you’ve done the IFD configuration and before you attempt to log in with the CRM for Tablets app.

Another aspect is the requirements imposed by the new Windows 8.1 version of the tablet app. Because of the changes on the OS layer, it’s no longer possible for Win8 apps to connect to any random server at will, but rather the developer has to specify the URL’s of these servers before publishing the app to the Windows Store. For CRM Online the domains for the service are known in advance, but for an on-premises deployment they could be absolutely anything. To overcome this, you’ll need to add a registry entry onto your device before attempting to connect to your server, otherwise the tablet app will just sit there and do nothing. Go to the page Set up CRM for Tablets, expand the section “what the admin needs to do” and grab the Powershell script from there. Running it on your device will prompt you for the CRM organization URL and create the necessary registry key for you. [Read more…]

Windows 8, Outlook 2013 and Dynamics CRM – part 2

Windows 8, Outlook 2013 and Dynamics CRM – part 2

Back in August I wrote about my initial experiences of using a Windows 8 PC with Office 2013 to connect the Outlook client to Microsoft Dynamics CRM. During that time we only had the preview versions of both the OS and Office, so some quirks were naturally to be expected. Now that Windows 8 is generally available and also the RTM bits of Office 2013 can be downloaded from MSDN (with commercial launch expected by end of January), it’s a good moment to revisit the topic. Upon my latest test I came across a few configuration gotchas that I though might be useful to share for anyone who’s struggling with the same issues.

Connecting to CRM Online with WLID

Our official work setup is still on Windows 7 / Office 2010 level, but being the kind of eager early adopter that I am, my home PC’s have moved to the brave new world of Windows 8 some time ago already. I installed Office Professional Plus 2013 on a Windows 8 64-bit laptop that’s not joined to a domain, so my login credentials to Windows are linked to my Microsoft Account (previously known as Windows Live ID). In my first tests in August this was a blocker for using a CRM Online organization where the user’s WLID / Microsoft Account was different in CRM and on the local machine.

Update Rollup 11 removed the need to manually enable Windows Identity Foundation (WIF) on Windows 8, but out of old habits I checked that it was available before configuring CRM. Launching the CRM client Configuration Wizard and selecting CRM Online on the Server URL field of the Configure Organizations prompt gave a familiar error: “Cannot connect to Microsoft Dynamics CRM server because we cannot authenticate your credentials.” Just like before, it appears that the Configuration Wizard automatically attempts to use the Microsoft Account of the local user for logging in to CRM Online. Logging out of the account in Internet Explorer and then logging in to CRM Online in the browser didn’t seem to resolve the issue with the Outlook client connectivity, as a further error message was presented later in the Initializing the Organization phase:

There is a problem communicating with the Microsoft Dynamics CRM server. The server might be unavailable. Try again later. If the problem persists, contact your system administrator.
[Expanded Information]
Unable to load the native components of SQL Server Compact corresponding to the ADO.NET provider of version 8082. Install the correct version of SQL Server Compact. Refer to KB article 974247 for more details.

The KB article referenced in the error message discusses the following issue: “You receive an error message when you run a SQL Server Compact 3.5-based application after you install the 32-bit version of SQL Server Compact Edition 3.5 Service Pack 2 on an x64 computer.” However, downloading and installing the x64 version of Microsoft SQL Server Compact 3.5 Service Pack 2 for Windows Desktop didn’t resolve the CRM configuration error, so I opened a support ticket with Microsoft. They instructed me that I also needed to install the Cumulative Update 2 for SQL Server Compact 3.5 Service Pack 2, which is a hotfix that you need to request a download link to be sent to you by email. After my SQL CE 3.5 had been updated to build 3.5.8082.00, I was finally able to connect my Outlook 2013 with our CRM Online demo organization.

Connecting to CRM on-premise with IFD

During the previous test with CRM Online I had also tried to connect the Outlook 2013 CRM client  to our production on-premise CRM server that is IFD configured. I kept receiving the following error: “Cannot connect to Microsoft Dynamics CRM server because we cannot authenticate your credentials. Check your connection or contact your administrator for more help.” Looking at the error details there was a message claiming “no credentials are available in the security package.” [Read more…]

Breaking down the Polaris and Statement of Direction documents

Breaking down the Polaris and Statement of Direction documents

After the announcement in July 2012 regarding the delayed delivery schedule of the CRM Anywhere functionality, Microsoft has been promising that their updated product roadmap would be announced “soon”. Well, it took until November eventually, but we now have two new documents available from them: the Statement of Direction and Microsoft Dynamics CRM December 2012 Service Update Release Preview Guide. In this post I’ll share a few thoughts and questions that these documents have raised in my mind.

Polaris (Microsoft Dynamics CRM December 2012 Service Update)

Much of the contents of Polaris was revealed in eXtreme CRM 2012 Las Vegas and tweeted out into the online communities. One major piece of news from there is only casually mentioned in the beginning of the Release Preview Guide document, so let’s emphasize it here once more:

This document is organized to highlight specific investments included in the December 2012 Service Update for Microsoft Dynamics CRM Online. This release begins in mid-December 2012 and will continue through January 2013.

Yes, on-premise and hosted customers will still need to wait another 6 months while the new functionality is previewed in the cloud. The Orion release, currently scheduled for around mid-2013, will include these new treats into the CRM server bits you can download and deploy on your own or outsourced hardware. In the meantime, there will be a gap during which some UI customizations and development can be done only in CRM Online, so remember to take this into consideration when planning you solution deployment strategies.

The new Flow UI, also known as the “Process-Driven UI” or “Refresh UI”, has been shown from the user’s point of view already earlier, but in the Release Preview Guide we get a first glimpse into the configuration options of how you can actually adjust it to match your real business processes. The Process Control Customization Tool appears to consist of a basic set of stages and steps, with no direct connection to the familiar workflow or dialog processes. Of course if you trigger a workflow process from a field value change you could include much more business logic into the stages and steps. The document mentions that there will be “several pre-defined steps such as locate existing contact and account”, so we’ll need to wait and see if the process steps will actually provide a new extension point that allows developers to create custom steps.

Ever since the Yammer deal in June, we’ve all been wondering (well, perhaps it’s just me who’s obsessed with these things) how this social business tool would be integrated into Dynamics CRM and specifically what it will do to the Activity Feeds functionality introduced in Q4 2011 Service Update. Looking at the Polaris UI preview, we still don’t have too many details about this, but at least there’s a screenshot for us to stare at. Back in July when the Flow UI was first shown, the Activity Feeds were presented on the opportunity form alongside activities and notes/attachments, but now it’s been replaced by a Yammer feed. However, the distinction between auto posts and user posts in the menu suggests that there’s a bit of the CRM Activity Feeds functionality in play here, since Yammer doesn’t have such concepts in their own product.

Showing updates regarding CRM records in the Yammer UI was already possible before Microsoft bought Yammer, thanks to the integration they had developed. In the release preview guide we can now read that “Microsoft will enable the ability to post messages from Microsoft Dynamics CRM to Yammer and vice versa”, which suggest a deeper level of integration, most likely leveraging Yammer’s Enterprise Graph. I guess it’s safe to say by now that the CRM R8 beta functionality developed for CRM Activity Feeds to filter the feed content has been permanently cancelled and all the efforts are aimed at integrating Yammer into Dynamics CRM. However, Microsoft will probably not completely rip out the existing feeds from on premises Dynamics CRM deployments nor implement a non-cloud Yammer, so the transition may take a while. Another thing worth noting is that the current free version of Yammer does not support any integration to applications like CRM, so the Enterprise Plan for Yammer may be required in order to leverage the new functionality in Dynamics CRM unless Microsoft changes the pricing policy.

Bing Maps integration will be available for the Flow UI, where “addresses for contacts and accounts will be displayed in an embedded contextual map provided by the Microsoft decision engine Bing”. There were some good comments to my previous Future Stars blog post about the licensing of Bing Maps, so you might want to check them out if visualizing your customer addresses on an integrated map is of interest to you. Just like with Yammer, currently the Bing Maps API requires a separate license when used in internal applications and there’s no mention of any changes to this model in the release preview guide, so it’s best to assume that these new Polaris features will not be free to users with a Dynamics CRM Online license alone.

Cross-browser support arrives with Polaris, but it’s a bit of a “yes and no” regarding support on iPad Safari browser. Yes, users will be able to access something else than Mobile Express on their iPad, but it’s not the same browser client as you’d have on a PC or Mac. A special version of the web client has been created for the iPad only, utilizing the new Flow UI forms. However, as the Flow UI is only available in a limited number of entities so far, only the “sales experience” is enabled in the iPad CRM client version. Judging by the menu below you can only access accounts, contacts, leads and opportunities. Any other entities (presumably even quotes, orders or products) will require you to click the “Launch Mobile Express” link, which will take you back to the CRM experience designed for pre-iPhone era smartphones. The Polaris version of iPad client seems therefore like an intermediate solution while we await for the full tablet UX to arrive.

So, where’s the Dynamics CRM Mobile part of the CRM Anywhere release? Hmm, not mentioned in this document, so let’s check out the long term roadmap next.

Statement of Direction, November 2012

This document discusses the Dynamics CRM product vision for the next 36 months and is therefore much less specific on the upcoming functionality than the Polaris release documentation. It starts with a list of upcoming applications to be added into Dynamics CRM in future releases. Putting the terminology into context, an example of a new application for CRM 2011 was goal management, so these would likely include a bunch of new default entities, business logic, UI enhancements and potential new integration points.

On the SFA front we’ve got Quote, Order, and Pricing Management, which is a very important area for Dynamics CRM to step up it’s game. Anyone who’s ever demoed the existing UI for creating quotes knows that the popup jungle is something you want to avoid showing to potential customers, so a more flat user experience for working with product lines . In the Service section the term Knowledge Management brings a breath of canned air from the past decade, especially when we later on hear that “SharePoint will power next-generation content and knowledge experiences to strengthen supporting business processes”. All joking aside, it’s pretty obvious that the KB functionality in Dynamics CRM is in need of a makeover, so bringing SharePoint into the picture is the obvious route for Microsoft to improve its CRM offering for service users.

The direction of marketing functionality development in Dynamics CRM will be shaped by Microsoft’s latest acquisition, Marketing Pilot. Although no one seems to have heard about the company before the MS press release, that doesn’t mean it wouldn’t be a good choice for the foundation which the v2.0 of Dynamics CRM marketing module would be built on. Whereas Skype and Yammer were big existing brands with their own technology stack, MarketingPilot is a small company that has developed their product on top of Microsoft’s platform and should therefore be much more easily assimilated into the Dynamics CRM product. Not a big splash like’s acquisitions of Buddy Media or Radian6, not even close, but Microsoft have said marketing automation is one of their key investment areas for CRM, so let’s wait and see how that story develops.

While not exactly a bullet point in the Statement of Direction document, it’s pretty clear that Surface will be the central vehicle for launching the re-imagined Dynamics CRM experience and Microsoft have come up with a nice promotional video to build up the hype while we wait for the Windows 8 app to arrive. Folding the “Metro CRM app”, Yammer, Skype and Surface all into one sure does result in a compelling image of what the next generation of customer relationship management applications could be like.

What about devices other than the Surface? More precisely: what about mobile as in smartphone apps? Unfortunately there’s not much to say about them, except that there’s another delay for supporting iPhone and Android devices. Even the upcoming Windows Phone 8 customers won’t initially be able to use their mobile device for more than reading CRM records and posting Activity Feeds posts with the existing Microsoft Dynamics CRM Mobile client.

The February 2012 announcement of Microsoft partnering with CWR Mobility pretty much put everyone in a waiting mode, as the official mobile client for Dynamics CRM would have obviously been the safest bet for any customer or partner. Well, by now we can clearly see that the deal is off and the CWR client is no more “official” than Resco, TenDigits or any other ISV offering. Instead of buying a solution, Microsoft eventually decided that they need to be the ones who build it. In the long run I believe this is definitely the right strategy for them, as mobile is simply far too important to be an outsourced component of CRM.

We’ve heard from the Dynamics team that they’re betting big on HTML5 to deliver experiences across different devices. Even though Facebook famously backed off from their HTML5 strategy in favor of native apps, I’m somewhat optimistic that the path chosen by Microsoft can work better in the business apps landscape. MS will naturally build native CRM clients for Windows 8 and Windows Phone 8, but the effort required in delivering an enterprise scale mobile solution for a fragmented Android platform probably doesn’t make sense to them. Those are the gaps that ISV’s are there to fill, delivering more advanced offline clients for non-MS mobile platforms.

At the same time as the device specific offering is being rearranged, we’ve heard from a source claiming to have official confirmation from Microsoft that the Dynamics CRM CAL price will soon be increasing by 15 percent, in preparation of the upcoming support for more devices per user. Since there will not be any additional 30 USD monthly fee per mobile user, the user CAL can be leveraged on more devices and therefore it delivers more value to customers, which in turn means Microsoft sees it can justify a price increase. Although no one ever rejoices when the cost of a service goes up, I’m actually in favor of a pricing strategy where the mobile and tablet clients will be as easy as possible for any Dynamics CRM users to access, rather than the customer organizations having to go through the internal negotiations of who really needs a premium license for mobile CRM usage. There’s always the device CAL for those who need to just enable CRM access on a single PC per user, after all.


Polaris is certainly an important update for Dynamics CRM and in many ways it feels like the starting point for “the next chapter” of the product. With all the UI and client changes lined up for Orion in mid-2013, in my mind it raises the question that will this already be a fully new product á la Microsoft Dynamics CRM 2013? Any which way, I think Microsoft is right now delivering a compelling vision with their whole product portfolio and announcements this year, and this reflects positively on the Dynamics applications as well.