SAP Knowledge Base Article - Public

3209052 - User able to login with both SSO and Password URL - SAP SuccessFactors

Symptom

SSO users are able to login to the SuccessFactors system by using both SSO and PWD url



Environment

SAP SuccessFactors HXM Suite

Reproducing the Issue

> End user with login method set to "SSO"  logs in to successfactors using SSO URL  

> Then the same user logs in to SF using PWD URL and is authenticated as well on the same device

Cause

Expected behavior for user who were once authenticated in the system via SSO

Resolution

This is an expected behavior for SSO users when they click on the PWD URL. Since they are already once authenticated via SSO, they will get get reauthenticated against that same session upon hitting the PWD URL.

Even if a SSO user inputs wrong password in the PWD login page, they will get authenticated due to seamless login on the basis of the username, if there is an active SSO session.

 

This behavior will not be the same for PWD users. When they hit the SSO URL , they will not get authenticated and will be redirected to SSO login.

Keywords

SSO , PWD ,seamless login , KBA , LOD-SF-PLT-LPG , Log In Page Issues (Non SSO) , Problem

Product

SAP SuccessFactors Platform all versions