kasmtech / workspaces-issues

18 stars 3 forks source link

[Bug] - Entra ID - SAML SSO #529

Open fstelte opened 3 months ago

fstelte commented 3 months ago

Existing Resources

Describe the bug Logging in with SAML SSO based on Entra ID I receive the error "Authentication method 'X509, MultiFactor, PasswordlessPhoneSignIn' by which the user authenticated with the service doesn't match requested authentication method 'Password, ProtectedTransport'. Contact the KASM application owner."

A search on the internet states this: RequestedAuthnContext is an optional value sent from SAML app to Azure AD. So please ask the application developer/vendor if it could be removed from SAML Request. Or if they can add ‘Unspecified’ method to RequestedAuthnContext

To Reproduce Steps to reproduce the behavior:

  1. Go to 'my kasm instance
  2. Click on 'login with Entra ID
  3. See error

Expected behavior An SSO experience

Workspaces Version Version 1.15

Workspaces Installation Method Single Server

Client Browser (please complete the following information):