Error AADSTS50011 or AADSTS50105 When Trying To Authenticate Via IAS
Error AADSTS50011 or AADSTS50105 When Trying To Authenticate Via IAS
Error AADSTS50011 or AADSTS50105 When Trying To Authenticate Via IAS
Symptom
When trying to activate IAS, the user is receiving reply URL faulty error:
The user is receiving the error AADSTS50011 when trying to sign in to an application that has been set up to use Azure AD
for identity management using SAML-based SSO:
The user is receiving the error AADSTS50105 when trying to sign in to an application that has been set up to use Azure
AD for identity management using SAML-based SSO:
AADSTS50105: Your administrator has configured the application SAP SuccessFactors Preview SSO to
block users unless they are specifically granted ('assigned') access to the application. The signed in user
'xxx' is blocked because they are not a direct member of a group with access, nor had access directly
assigned by an administrator. Please contact your administrator to assign access to this application.
Environment
SAP SuccessFactors HXM Suite
Cause
This error is on the Azure side, the AssertionConsumerServiceURL value in the SAML request doesn't match the Reply
URL value or pattern configured in Azure AD. The AssertionConsumerServiceURL value in the SAML request is the URL
you see in the error.
The customer is using a custom domain that is not configured correctly.
Resolution
To fix the issue, follow these steps:
1. Ensure that the AssertionConsumerServiceURL value in the SAML request matches the Reply URL value
configured in Azure AD.
2. Verify or update the value in the Reply URL textbox to match the AssertionConsumerServiceURL value in the
SAML request.
As an example, refer to the following article for detailed steps about how to configure the values in Azure AD:
Tutorial: Azure AD SSO integration with Salesforce
Note: The reply URL is also known as Redirect URI. These values depend on what application is being used. You
should get the values from the application vendor.
After you've updated the Reply URL value in Azure AD, and it matches the value sent by the application in the
SAML request, you should be able to sign in to the application.
See Also
https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/error-code-aadsts50011-reply-url-mismatch
https://docs.microsoft.com/en-us/troubleshoot/azure/active-directory/error-code-aadsts50105-user-not-assigned-role
Keywords
Reply URL faulty, Identity Provider, Azure, AssertionConsumerServiceURL , custom domain, AADSTS50011, SAML-based
SSO, AADSTS50105
Attributes
Key Value
Requires Action 0
Products
Products