<html><body><div dir="ltr">Have you successfully configured Bomgar (BeyondTrust) for SSO via your Shibb IdP ?<div><br></div><div>Bomgar (BeyondTrust) has a GUI for SAML SSO integration that is mostly clear and straightforward,<div dir="ltr">but seemingly appropriate SAML assertions trigger “Authentication Failed” message at the service</div><div dir="ltr">(with no further details).</div><div dir="ltr"><br></div><div dir="ltr">Incoming SAML request specifies a nameid-format:persistent (not mentioned in the GUI) so</div><div dir="ltr">I configured release of nameID based on uid (unscoped username) and ePPN (same username, @<a href="http://alaska.edu">alaska.edu</a>)</div><div dir="ltr">with the requested format. Neither alternative produced anything further than “Authentication Failed” at the service.</div><div dir="ltr">Support has so far been less than useless. Perhaps you know an additional unmentioned requirement or trick?</div></div><div dir="ltr"><br></div><div dir="ltr">David St Pierre Bantz</div><div dir="ltr">U Alaska IAM</div></div></body></html>