You need to ensure that when users log on to clientcomputers, they are added automatically to the local Administrators group
You need to export the token-signing certificate from ADFS1, and then import the certificate to ADFS2 and ADFS3.