如何在ADFS中配置基于SAML的SSO信赖方信任?SP发起式登录故障排查
Troubleshooting SP-Initiated SSO Issues with ADFS
Hey there, since you’ve got IDP-initiated SSO working but SP-initiated is failing, that tells us the core trust relationship between your SP and ADFS is functional—so we can narrow down the issue to SP-specific configuration details. Here’s a step-by-step breakdown to fix this:
Verify Relying Party Identifier (Entity ID) consistency
Double-check that the Entity ID configured in your ADFS Relying Party Trust matches exactly what your SP is sending in its SAML request. Even small differences like trailing slashes, case sensitivity, or typos will break SP-initiated flows. This is one of the most common culprits.Validate Assertion Consumer Service (ACS) Endpoints
In your ADFS Relying Party Trust settings, navigate to the Endpoints tab. Ensure you’ve added the correct ACS URL for your SP (this is where ADFS sends the SAML assertion after authentication), and that the binding is set toHTTP-POST(the standard for SP-initiated flows). The ACS URL must match what your SP expects—no exceptions.Audit your trust.xml metadata
The sample trust.xml you copied might have placeholder values (like default Entity IDs or ACS URLs) that don’t match your actual SP. Open the file and confirm:- The
<md:EntityDescriptor>’sentityIDmatches your SP’s Entity ID - The
<md:AssertionConsumerService>location points to your real ACS URL - The certificate in
<md:KeyDescriptor>is your SP’s valid signing/encryption certificate
If any of these are incorrect, update the file and re-import it into ADFS, or manually adjust the Relying Party Trust settings to match.
- The
Check algorithm compatibility
Go to the Advanced tab in your Relying Party Trust settings. Make sure the secure hash algorithm (e.g., SHA-256) matches what your SP uses for signing requests. If there’s a mismatch, ADFS will reject the SP’s SAML request outright.Enable ADFS logging for detailed error insights
Fire up the Windows Event Viewer, then navigate toApplications and Services Logs > AD FS > Admin. Look for events with Event ID 364 (failure audits) or 1202 (error details). These logs will tell you exactly why the SP-initiated flow is failing—whether it’s a signature validation error, invalid ACS URL, or missing RelayState parameter.Validate the SP’s SAML request
Use a browser extension like SAML Tracer to capture the SAML request your SP sends to ADFS. Check that:- The
Destinationattribute points to your ADFS login endpoint (usuallyhttps://<your-adfs-server>/adfs/ls/) - The
AssertionConsumerServiceURLin the request matches what’s configured in ADFS - The RelayState parameter is properly formatted (ADFS expects it to be a URL-encoded string, if used)
- The
Since IDP-initiated SSO works, the core trust is intact—so the fix is almost certainly in one of these SP-specific configuration gaps. Start with the Entity ID and ACS checks first, as those are the most frequent issues.
内容的提问来源于stack exchange,提问作者Elbin

