Use JumpCloud SAML Single Sign On (SSO) to give your users convenient but secure access to all their web applications with a single set of credentials. Use this page to troubleshoot common SAML Single Sign On (SSO) errors and connection issues. We’ll continue to update this KB as we discover new solutions to SAML-related issues.<\/p>\n\n\n\n
The following terms are used frequently:<\/p>\n\n\n\n
Service Provider (SP) Initiated SSO<\/strong>:<\/p>\n\n\n\n
<\/p><\/div>
This example does not include the workflow for JIT or Just-In-Time Provisioning<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Identity Provider (IdP) Initiated SSO<\/strong>:<\/p>\n\n\n\n
Service providers can differ in their SAML\/SSO configurations, features, and functionality. Use the troubleshooting tips we provide and refer to the support pages provided by the SP vendor.<\/p>\n\n\n\n
Take a moment to compare settings.<\/strong><\/p>\n\n\n\n
Review your current configuration against the configuration the SP recommends in their documentation. <\/p>\n\n\n\n
Does your SP actually support SAML 2.0?<\/strong><\/p>\n\n\n\n
It\u2019s rare but some SPs support other versions of SAML.<\/p>\n\n\n\n
Is your certificate valid?<\/strong><\/p>\n\n\n\n
Are you using optional attributes?<\/strong><\/p>\n\n\n\n
Can you successfully configure the SP using the GENERIC SAML 2.0 connector?<\/strong><\/p>\n\n\n\n
If so, there\u2019s an issue with the pre-built connector. See SSO using Custom SAML Application Connectors<\/a>.<\/p>\n\n\n\n
Users are implicitly denied access to applications. After you connect an application to JumpCloud, you must authorize user access to that application. See Authorize Users to an SSO App<\/a>. <\/p>\n\n\n\n
How is the workflow being initiated?<\/strong><\/p>\n\n\n\n
Why isn’t JIT working?<\/strong><\/p>\n\n\n\n
What, if any, information are you getting from error messages?<\/strong><\/p>\n\n\n\n