ShibIdP v4 & Azure SAML Authentication Issue with RequestedAuthnContext

Janusz Ulanowski janusz.ulanowski at heanet.ie
Thu Jan 11 09:07:35 UTC 2024



We are using ShibIdP v4 as the IdP SAML proxy to Azure. It has been a while since I last worked on ShibIdP. Currently, I am trying to find a workaround for an issue that some users are experiencing.

When the IdP receives a SAML request from the Service Provider (SP) with RequestedAuthnContext and Comparison="exact," it passes that request to Azure. However, some browsers like Edge store the previous session and use X509 certificates with Azure IDP, leading to a validation failure due to an authRequest mismatch. The error on the Microsoft login site is AADSTS75011.

I am struggling to figure out how to override this behavior. Has anyone encountered a similar issue and found a fix for it?"
Thanks in advance

--

Janusz


More information about the users mailing list