The AD FS Web Agent Authentication Service was not able to start. The authentication service has not been configured to run ...

The AD FS Web Agent Authentication Service was not able to start. The authentication service has not been configured to run as a principal that has been granted the "Impersonate a client after authentication" privilege (SeImpersonatePrivilege). 

Users will not be able to access protected resources until the authentication service can be restarted. 

User Action 
Either grant the AD FS authentication service principal the "Impersonate a client after authentication" privilege or configure the service to run as a principal that has already been granted the "Impersonate a client after authentication" privilege. (For example, configure the authentication service to run as LocalSystem.) This privilege is granted by default to the SERVICE group, but on a hardened server it may be necessary to grant the privilege explicitly.