Troubleshoot SSO Connections
Fix common Single Sign-On (SSO) sign-in and configuration problems.
Common Issues
This table lists common symptoms and how to fix them:
| Symptom | Likely Cause | Fix |
|---|---|---|
AADSTS650056 — misconfigured application | Entra's Identifier (Entity ID) does not match the issuer Haystack Platform sends | Set Entra's Identifier to exactly the value in the connection's IdP issuer / entity ID field |
AADSTS50011 — reply URL mismatch | The Reply URL in Entra does not exactly match the ACS URL from Haystack Platform | Re-copy the ACS URL from the connection details, trailing slash included |
AADSTS50105 — user not assigned | Assignment required? is Yes and the user is not assigned, or is only in a nested group | Assign the user or their direct group under Users and groups |
| Sign-in fails right after authenticating at your provider | The email address sent by your provider does not match any invited Haystack Platform member | Invite the person first, or correct the email claim so it matches the invited address |
| Signature verification fails | Wrong certificate (Raw instead of Base64), expired certificate, or your provider signs only the response and not the assertion | Re-download Certificate (Base64). In Entra, confirm the Signing Option is Sign SAML assertion or Sign SAML response and assertion |
| Entering an email does not redirect to the provider | The domain is not listed on the connection, or the connection is disabled | Check the Email domains field and the enabled toggle |
| Saving the connection reports a conflict | One of your domains is already claimed by another connection | Contact Haystack Platform support |
| No signing certificate under Advanced options | It is issued when you first save with request signing turned on | Save the connection with Sign AuthnRequests on, then reopen it |
| Sign-in worked for years, then stopped | Your provider's signing certificate expired | Renew it and update the connection |
If you're still stuck, contact Haystack Platform support with your connection's display name, the time of the failed sign-in, and any error code your provider showed.
What To Do Next
Was this page helpful?