MobiControl with ADFS SSO

CB
Carsten Baumert
KIRCHHOFF Automotive GmbH

Hi Support-Team,

I switched from internal user authentication to Active Directory based and it is working great, now I wanted to add SSO but cannot get it working. The website jumps to "Invalid response received from Identity Provider.", the server log shows "Invalid SAML 2.0 message. Element 'StatusCode' value is wrong. Expected 'urn:oasis:names:tc:SAML:2.0:status:Success' received 'urn:oasis:names:tc:SAML:2.0:status:Responder'".

We are running ADFS 3.0, groups setting is set to Directory. Any ideas what went wrong?

Thanks and cheers

Carsten

4 years ago
SOTI MobiControl
ANSWERS
D
DRMOD@SOTI
4 years ago

HI Carsten Baumert

Thank you for requesting a response from SOTI Support Staff. 

Something that could be wrong is if the request is being denied by the values. you would need to check if the comparison value and the actual value are matching and if there is an authorization exception. Please check if you have something like this  <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied"/> This issue can require log analysis.


May I ask if you have tried the configuration here as below?

please refer to this link for the details of the configuration:

https://www.soti.net/mc/help/v14.5/en/console/reference/dialogs/globalsettings/identityprovidermanager.html

Can you please send the following two things:

1. A screenshot of the error message you had on SAML
2. A screenshot of the page like below:

I look forward to hearing back from you.

Kind Regards,

CB
Carsten Baumert
4 years ago

Hi DRMOD@SOTI,

thanks for the reply. I made some screenshots and attached them, let me know if you need anything else. 

Kind regards

Carsten Baumert

D
DRMOD@SOTI
4 years ago

Hi Carsten Baumert

Thank you for the information provided.

As I can see there is a significant amount of information that requires testing and deep analysis. I would recommend that you create a support case(click here) or call SOTI Support team(click here) to raise this issue. You can reference this post, so that the Soti support team can investigate this issue further.

Please let us know your experience and if you find a solution. Thank you.