Common SSO Issues in the Login Flows
- If nothing happens when you attempt SSO from IDC side (no redirect), IDC might not have your company set to SSO mode yet. They can enable that so that hitting
saml-welcomeor clicking a button triggers it. - If user gets to IdP and logs in, but then gets sent back to IDC’s login page or sees an error, likely something in the SAML response wasn’t accepted. Check IDC’s error message if any. The SAML Response could be unsigned or signed with the wrong cert, or missing attributes. Ensure signing certificate is the one in metadata and that IDC has that cert.
- Case sensitivity or format mismatches for attributes can also cause subtle issues – e.g., maybe you sent GivenName attribute but IDC expected GivenName (shouldn’t matter if URIs are same, but ensure no typos).
In summary, both SP and IdP initiated SSO are supported by IDC. SP-initiated is the default and recommended for ease of use (users can just use IDC’s normal URL). IdP-initiated is available if you want it. Proper testing of both ensures a smooth SSO experience for your users.