Symptom
SAP Jam login post session timeout shows error message when Jam is connected with a SuccessFactors instance that uses Identity Authentication Service (IAS) for user authentication.
"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."
Environment
SAP Jam Collaboration
Reproducing the Issue
Pre-Requisite
- The SAP Jam tenant should be using SuccessFactors(BizX) as Identity Provider.
- The concerned BizX tenants should be connected to Identity Authentication Service (IAS) for user authentication.
Replication Steps
- Login to SAP Jam.
- Leave the browser open for 30 mins without any activity, to let the session time out.
- The session timeout popup will be shown.
- Click Log In again on the session timeout popup.
- The user will be taken to the SF authentication flow again.
- But, post the authentication, the user will see a BizX error page instead of being redirected to Jam.
Resolution
It is necessary to change the "Session timeout redirect URL". This can be done:
Via "SAML 2.0 Single Sign On":
You can access the Manage SAML SSO Settings in "Admin Center" > "Tools" > "SAML 2.0 Single Sign On" and change the URL as described on the "Configure the URL redirect links" section of KBA 2569087. If the Corporate IdP entry is already created in that screen, just edit and input the redirect URLs as needed.
More about the steps, check KBA 2768478 - [SSO] How to change redirect URLs for Single Sign On - SAP for Me.
Or via SuccessFactors provisioning:
- Access provisioning.
- Go to "Single Sign-On (SSO) Settings".
- Set the following as Session timeout redirect URL. The <company_id> part should be replaced with the SuccessFactors Company Id.
- /saml2/Login?company=<company_id> - Example-
Keywords
Session timeout error,login error,saml2 context,Jam session timeout , KBA , LOD-SF-JAM , SAP Jam , Problem