Skip to main content
Lorena Mosquera a posé une question dans #Security
We have an issue with a client's SSO account- it's affecting only 1 user out of 9. 

We have one user, who is unable to log in via Single Sign-On- everyone else in the org is able to use SSO without issue. We have confirmed all the profile settings and nothing is different from his profile compared to the others. We receive an error message saying SSO can not be verified yet the log in history doesn't even show the attempt at the verification.

Here are the issues/steps we have taken to try to correct without success:

1- Compared his log in credentials to other users to confirm Federated ID is in place where it should be.

2-Confirmed the same access rights.

3-He had a prior user name (like all the other users had) with another organization (two law firms split practice, one org became two orgs). The user name has been changed and deactivated in the prior org. Yet whenever we try to create the user name we want it comes back with user is already in use in a SF org.

4- While issue ⌗3 is annoying it should not stop the federated id from working. Federated ID doesn't connect to the SF system at all. NOTHING shows in history though the error messages appear saying it could not be verified.

5-We have checked the community cases and posts- none of the suggestions have worked.

6-Sandbox suggestion as listed here- not the case as sandboxes are not in place for this org. https://developer.salesforce.com/forums/?id=9062I000000IVuJQAW

7-Deactivate and create a new profile in the new Org- done.. did not fix the issue.

8-check the Azure credentials to ensure that the profile settings are the same for all users from an Azure Directory perspective. Confirmed... nothing is different.

9-We do not utilize safe network IP addresses so this is not something that could be limiting access.

10-we do not utilize named credentials either so this is not something that could be limiting access.

11-We have tried to FREEZE and then UNFREEZE the user without success.

12-User can log in without issue if he uses a user name and password access only.

13-Self Signed Cert for single sign-on is active and valid.

14-Federation ID is NOT case sensitive but has been tested using both case and non-case sensitive entries.

15-SAML Identity is using the assertion that contains the Federated ID from the user object.

 
2 réponses
0/9000