Domain SSO Was Configured On The IAM But User Single Sign-On Is Not Successful

|
  • 274
  • 6

Issue Description

Domain SSO was configured on the IAM but user single sign-on is not successful.

Handling Process

1. Check the configuration on the IAM. The authentication policy selects single sign-on. In the single sign-on, the domain single sign-on is selected.
2.Found that the number of recent users obtained by domain SSO is zero, the test validity prompt failed.

3.Check the audit logs inside the domain server, audit account logon events and audit logon events has been enabled.



4.Found out that the domain account permissions are not enough, change to the administrator account and it works normally.


Root Cause

The domain account does not have permission to scan the security logs in the domain server.

Solution

Change the domain account to an account that have permissions to scan the security logs.

Suggestions

Recommended to use the administrator account when selecting the domain account in domain SSO.
Faisal Posted 13 Aug 2020 07:41
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 11 Sep 2020 02:22
  
Thank you for sharing the information
Faisal Posted 31 Oct 2020 09:39
  
Nice article ...
Faisal Posted 08 Dec 2020 07:31
  
Great Info
Faisal Posted 11 Mar 2021 09:55
  
Very informative …
Faisal Posted 27 May 2021 14:21
  
Nice guidance ...

I want to write a case
Doc ID: 2635
Author: Newbie280530
Updated: 2019-12-24 11:46
Version: