Single Sign-On Error Messages

Prev Next

You might see some error messages after Single Sign-On to log on to ePO - On-prem.

This table lists error messages and their description for troubleshooting.

For details about product features, usage, and best practices, click ? or Help.

Error Messages

Description

Suggested Solution

SAML authentication is successful. Close your browser to end your session and contact your administrator for ePO permissions grant.

After successful SAML authentication, user will be redirected to intermediate ePO page and user will see this message. Same IdP user is created in ePO - On-prem with ‘SAML authentication type’ without any permissions.

User has to contact the ePO Administrator to get the required permissions. Once Administrator assign the permission, user can again log in into ePO - On-prem through identity provider credentials.

User already present in ePO with different Authentication Strategy. Close your browser to end your session and contact your administrator.

If IdP user is already present in ePO - On-prem with different authentication types like ePO, MVISION, or certificate based authentications, then single sign-on will not work. You will then come across this error message.

We can’t have same user with different authentication type. You have to delete the existing user for single sign-on to work.

There is an internal error trying to log on to the server. Contact technical support (when trying to do Single Sign-On to ePO - On-prem).

This error occurs when:

  1. If Identity Provider Entity Id in ePO - On-prem IdP settings is not matching with Entity Id (Issuer) in IdP application.

  2. If Identity Provider X 509 Certificate in ePO - On-prem IdP settings is invalid or does not match with the certificate available in the configured IdP application.

See orion.log for more details about the error message.

  1. Update the Identity Provider Entity Id in ePO - On-prem IdP properly. It must be same as of Entity Id (Issuer) in IdP application.

  2. Make sure Identity Provider X 509 Certificate in ePO - On-prem IdP settings is same as of certificate available in configured IdP application.

Not all error messages appear in the product interface.

Check the orion.log file for information about a particular error message or contact Trellix Support.