goauthentik / authentik

The authentication glue you need.
https://goauthentik.io
Other
12.77k stars 850 forks source link

Authentik 2023.10.6 user mating mode with email throws permission denied #8206

Open sdayu opened 8 months ago

sdayu commented 8 months ago

I implement Authentik with Azure ad using OAuth with User matching mode -> Link to a user with identical email address. Can have security implications when a source doesn't validate email addresses

It works as well until I upgrade to 2023.10.6. Authenthik throws the error shown below MicrosoftTeams-image

Can anyone suggest a configuration for me? Thank.

BeryJu commented 1 month ago

There were some bugs around azure AD around 2023.10.x iirc, can you try to edit the Azure AD source and re-set the OIDC Well-known URL based on the URL in the azure portal?