Version Affected: 9.x
Trying to use SP Initiated SAML with BrainSpace and it is not working.
The User is redirected to the IdP but the IdP errors after the User logs in.
Also BrainSpace acts like it is SP initiated - Eg, It redirects you from the SP to the IdP. It does not send an AuthN request.
Resolution: As BrainSpace does not send an AuthN request, you need to set the PostAuth tab to IdP Initiated rather than SP initiated.
1. Open the Web Admin Console
2. Navigate to the Post Auth page of the realm in question
3. Change to SAML 2.0 (IdP Initiated) Assertion
4. Hit Save
Ensue the Issuer and audience match the identifier on the Brainspace side of things
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.