Troubleshooting: SAML Deep Linking Fails, Users Land on the Application's Home Page Instead

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After single sign-on, a user can land on the application's home page instead of the specific page they were trying to reach. SecureAuth Identity Platform supports IdP-initiated deep linking, as long as the service provider or application itself supports receiving it. For a service provider (SP)-initiated setup, the service provider is responsible for handling the deep link, as long as the realm's Assertion Consumer Service (ACS) URL is configured correctly.
     

    Cause

    The realm's SAML Target URL field on the Post Authentication tab is set to a fixed page, which unconditionally sends every user there regardless of any deep link. It's also possible the deep link itself isn't being passed in the parameter the realm expects -- an IdP-initiated realm expects the deep link in a Target parameter, while an SP-initiated realm expects it in a RelayState parameter.

     

    Resolution:

    Check the following:

    1. In the Admin Console, open the realm and go to the Post Authentication tab.
    2. Clear the SAML Target URL field if anything is entered there. While it's set, every user is redirected to that URL regardless of any deep link.
    3. Confirm a SAML Consumer URL is configured. The service provider uses this to determine where to send the user once authentication completes.
    4. Configure a SAML Issuer, if the service provider requires one.
    5. Confirm the deep link is being passed in the parameter that matches the realm's SSO initiation type:
      • IdP-initiated: the deep link must be passed as Target (for example, ?Target=<url>).
      • SP-initiated: the deep link must be passed as RelayState.
      If the service provider requires RelayState specifically, change the realm's configuration from IdP-initiated to SP-initiated to match.


     

    Special Considerations

    Different applications have different deep-linking requirements, and this article may not cover every scenario. Contact SecureAuth Support for help with a specific integration -- new integrations may require additional fees.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.