ERROR REFERENCE
The errors SSO actually fails with.
One page per message, written for the person reading it at the moment a customer cannot sign in. What it means, what causes it, and how to confirm which cause applies.
AADSTS50008: SAML token is invalid
Microsoft Entra IDDraft · not indexedUsers are bounced back from the identity provider with AADSTS50008 and cannot complete sign-in.
AADSTS75005: the SAML request is not a valid protocol message
Microsoft Entra IDDraft · not indexedSign-in fails immediately at the Entra ID endpoint with AADSTS75005, before any credential prompt appears.
Certificate is not yet valid
Draft · not indexedSSO fails with a not-yet-valid, NotBefore or certificate validity error, while the certificate looks current in the portal.
IdP metadata changed without notice
Draft · not indexedSSO worked yesterday and fails today, with no deploy or configuration change on your side.
SAML assertion audience mismatch
Draft · not indexedThe service provider rejects the assertion with an audience restriction, AudienceRestriction or invalid audience error.
SAML signature validation failed
Draft · not indexedThe service provider rejects the assertion with a signature validation, signature verification or digest mismatch error.
Pages marked draft are written but not yet technically reviewed. They carry a noindex tag and stay out of search until someone has checked the protocol detail.
Want this watched for you?
Monitoring is being built now: daily scans of every connection, alerts at 90, 30, 7 and 1 day, and a report you can hand to your customer’s IT admin. Leave an address and you will hear when it opens.