Symptom
SAP Identity Authentication Service (IAS) is configured as a SAML 2.0 proxy, delegating authentication to MS Entra ID as the corporate Identity Provider.
The following error occurs when:
- Testing single sign-on directly from the MS Entra ID enterprise application, or
- Opening the enterprise application from https://myapps.microsoft.com:
Identity provider cannot process the response due to wrong configuration.
Please contact your system administrator.
In the IAS Troubleshooting Logs (severity: All), the following entry is recorded:
state=failed, action=authenticate, objectType=user,
message="User authentication failed. Cookie name is not valid"
If the application URL is opened directly in a browser, SAML 2.0 SSO works correctly. The error occurs only when the login is initiated from the MS Entra ID side (IdP-initiated flow).
Read more...
Environment
Identity Authentication
Product
Identity Authentication 1.0
Keywords
KBA , BC-IAM-IDS , Identity Authentication Service , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview