Troubleshooting: O365 Error AADSTS50107 Requested Federation Realm Object Does Not Exist

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After configuring Office 365 (O365) with SecureAuth, login attempts fail after authenticating and being redirected from SecureAuth to O365, with the error:

    AADSTS50107: Requested federation realm object 'https://secureauth.example.com/secureauth74' does not exist.

     

    Cause

    The Issuer set in O365 does not exactly match the Issuer set on the Post Auth page. The most common mistake is including a trailing slash in one and not the other.

     

    Resolution:

    1. Verify the IssuerUri by running the following in Azure PowerShell, replacing <DomainName> with the actual domain name (for example, Get-MsolDomainFederationSettings -DomainName secureauthdev.com):
    Get-MsolDomainFederationSettings -DomainName <DomainName>
    1. Open the SecureAuth Admin Console and navigate to the Post Auth page for the O365 realm.
    2. Correct the WSFed/SAML Issuer setting so it exactly matches the O365 IssuerUri verified in step 1.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.