and more in a single search tool across platforms. Read the announcement here. |
10/29/2023 07:18 PM
Hi all,
We have configured SAML SSO via Azure AD using the old SSO settings prior to 23.x.
SSO is working except for when the session expires / timeout.
When the session expires, the user is redirected to the OOPS! page which states that Saviynt wasn't able to find a user with that username and password.
When we click on "Please click here" to logout and try again, we are redirected to Azure account selection page and when we select the account, we are redirected back to the same error page above. The only way to log in again is to "Sign Out" of the account on the Azure account selection page and login again.
We have tried the following:
- Configuring Saviynt Logout URL
- Configuring Logout URL on Azure
- Set same session timeout values on Saviynt(sp) and Azure (idp)
- Set higher session timeout value on Saviynt (sp)
Appreciate any inputs on this please, thank you!
10/29/2023 08:16 PM
can you share conifgurations
10/29/2023 08:33 PM
Sure @rushikeshvartak ,
Here are the logout related configurations in auth.groovy:
grails.plugin.springsecurity.saml.maxAuthenticationAge=1800
grails.plugin.springsecurity.saml.afterLogoutUrl = '/logout'
grails.plugin.springsecurity.saml.logouturl='https://<xxxxxx>.saviyntcloud.com/logout'
Here are the configurations on Azure idp:
Entity ID: SaviyntSSO
Sign On URL: https://<xxxxxx>.saviyntcloud.com
Logout URL (Optional): https://<xxxxxx>.saviyntcloud.com/ECM/saml/SingleLogout/alias/SaviyntSSO
10/30/2023 12:51 PM
keep the maxAuthenticationAge value more than the session timeout value in IDP. Please note this value is in seconds in Saviynt. Recycle the services once the change is made.
Thanks,
Mohit Arora