SecureAuth Version Affected: All versions
Users are reaching the home page of the application instead of the intended page after single sign on. The SecureAuth IdP supports IdP-initiated deep linking, as long as the service provider or application supports it. For an SP-initiated setup, the service provider usually handles the deep linking, as long as the ACS is defined.
When using an IdP-initiated setup, ensure that there is no Target URL defined in the Post Authentication tab, and the deep link is passed by "?Target=".
There are a few things to check for this issue:
- Go to the SecureAuth Admin Panel > Post Authentication tab
- Remove any URLs defined in the SAML Target URL. If a URL is entered in this field, the user will always get directed to that link.
- Ensure there is a SAML Consumer URL defined. This is what usually handles the deep linking by the service provider.
- Include a SAML Issuer, if it is required.
- If vendor requires the deep link to be passed as "RelayState", then switch the configuration from IdP-initated to SP-initiated. For IdP-initiated, the deep link must be passed as "Target".
IdP-initiated = Target
SP-initiated = RelayState
Different apps have different requirements and this knowledge base article may not apply to every scenario. If you have any questions regarding this, please contact SecureAuth Support. Please note that new integrations may require additional fees.