Single Sign-On Error in Self Service

AntonyaJ
New Contributor III

I've had this come up a number of times on the admin site, but this is a first for the Self Service app. I don't want my users to have to run into this.  When I run into it, I have to clear all cache related to login.microsoftonline.com, or open in private/incognito. Not something that can be done with the app. What can I do to keep this from happening in the app at least?

We're Azure IdP. I have Self Service set to require login, and to use SSO.

Screen Shot 2022-04-28 at 9.27.08 AM.png

 

1 ACCEPTED SOLUTION

Justin13579
New Contributor III

I've tested and seen where if the SSO Token is set to never expire - this doesn't happen. That generally seems like a bad idea, but might point to the cause of the issue.

View solution in original post

7 REPLIES 7

nwiseman
Contributor

I wish I had an answer for this but I'm just here to bump it.

We're seeing the same thing on our console using PingID. Luckily we don't currently have Self Service setup for SSO, but this is becoming more and more of a headache for SysAdmins and IT Support. 

Justin13579
New Contributor III

I've tested and seen where if the SSO Token is set to never expire - this doesn't happen. That generally seems like a bad idea, but might point to the cause of the issue.

AntonyaJ
New Contributor III

I had it set to expire after 8 hours. I was recommended to not do Never Expire, but I'm testing it out atm just for funsies. We'll see what happens /shrug

jpeters21
Contributor II

Had this for a while as well.. I just come to always open a incognito window as I thought disabling to not be a best practice.. but can confirm Disabling SAML Token expiration did eliminate the issue. 

AntonyaJ
New Contributor III

Salesforce?

mikehill
New Contributor

Did you get anywhere with Jamf support on this?
We had the same issue for our admins logging onto JSS.
We just checking before we add all users to SSO via Self Service.

AntonyaJ
New Contributor III

After setting the token to never expire, I stopped having the problem.