Hi Simon,
Thanks for reaching out to us.
This error is shown when the Entity ID configured in the plugin doesn’t match the Entity ID configured in your Azure Enterprise Application.
You can find the correct value of the Entity ID in the miniOrange SAML SSO plugin by following these steps:
- Go to the Service Provider Metadata tab in the plugin.
- The Entity ID value is mentioned in the SP Entity ID / Issuer field.
To verify if this Entity ID is properly entered in your Azure application, please follow the steps below:
- Navigate to your configured Enterprise Application in Azure.
- Click on Single Sign-On from the left panel, and then click on the Edit button of the Basic SAML Configuration.
- Under the Identifier (Entity ID) section, please ensure the Entity ID is the same as in the miniOrange SAML SSO plugin.
Please don’t hesitate to contact us via the plugin’s support form for further assistance.
Thanks,
Anukasha
Hi Anukasha,
Thanks for getting back to me, we have checked the Entity ID which is the same.
The problem we are having is that the workflow when you get to the Enterprise application in Azure isn’t the same as what’s described in the instructions. There’s a link for Single sign-on in the right place, but it doesn’t have an edit button for the “Basic SAML configuration”. It actually refers to it as OIDC-based Sign-on.
Here’s what we get if we go to the application and click on Single sign-on: https://ibb.co/dpzZzgx
Following over to the App registration the overview shows: https://ibb.co/7SRzbgv
Somehow we then managed to get to an option to select a single sign-on method: https://ibb.co/hMX8gGY
However, if we click SAML we then get taken off to either publish our application in the gallery, or to “use the non-gallery feature to enable SAML-based single sign-on for applications that aren’t supported in the Microsoft Entra Gallery” which has a big list of applications, none of which mention SAML or OpenID Connect.
Many thanks,
Simon
Hi Simon,
Thanks for explaining the issue you are facing.
To enable SAML Single Sign-On, you will have to select the non-gallery app and create your own application, instead of selected a pre-added app.
All of these steps are mentioned here in our documentation – [ Office365 SSO Setup guide ]
Please follow the steps in the guide and feel free to reach out if you still face issues.
You can also reach out to us via the plugin’s support form so that we can schedule a meeting with you and help you resolve this issue at the earliest.
Thanks,
Anukasha