ERROR

Unable to login using Idp in ArcGIS Online. Unable to validate SAML response

Last Published: January 29, 2024

Error Message

The following error is returned when trying to access ArcGIS Online with configured enterprise logins:

Error:   
"Unable to login using Idp. Unable to validate SAML response"
image of error message

Cause

  • The configured Shibboleth certificates do not match. This error can be prompted when the authentication signatures for the sender and receiver Shibboleth certificates do not match. A mismatch in certificates can occur when a new Identity Provider (IdP) is configured but is not updated with the appropriate Shibboleth certificate.
  • The Active Directory Federation Services (AD FS) certificate has changed or is expired. If the certificate is expired, ArcGIS Online is unable to connect to the Security Assertion Markup Language (SAML) on the IdP server to authenticate enterprise logins.
  • Uploading the federation metadata file can return this error. This can be caused by a corrupt metadata file or if another application is using the metadata file.
  • Loss of trust relationship between ArcGIS Online and the IdP, which must be re-linked.

Solution or Workaround

  • Configure a working Shibboleth certificate. The following ArcGIS Online Help document explains this in detail: Configure Shibboleth.
  • Update the X.509 certificate in ArcGIS Online. The following ArcGIS Online Help document explains this in detail: Set up enterprise logins.
Note:
An SAML tracer tool is used to display network traffic being passed through, together with SAML request and response messages to troubleshoot Enterprise login issues. The following SAML tracer tools can be used with the following browsers: Google Chrome, SAML Chrome Panel and Mozilla Firefox, SAML tracer.

Article ID:000012930

Software:
  • ArcGIS Online

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Related Information

Discover more on this topic