# Azure AD Saml SSO not working - Invalid login. Please verify credentials

**URL:** <https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440>\
**Category:** Product Support\
**Tags:** mautic-4\
**Created:** [June 26, 2023, 9:41pm UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440 "2023-06-26T21:41:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasjitchopra](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jasjitchopra](https://forum.mautic.org/u/jasjitchopra)\
**Post date:** [June 26, 2023, 9:41pm UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/1 "2023-06-26T21:41:32Z")

</div>

**Your software**  
My Mautic version is: 4.4.9  
My PHP version is: 8.0.29  
My Database type and version is: 10.6.12-MariaDB-0ubuntu0.22.04.1  
My Setup: Ubuntu 22.04 - LAMP

**Your problem**  
My problem is: Configured SAML for Azure AD setup. Even the test from Azure AD is successful in issuing a token. After redirect to [https://mymauticsite/s/saml/login\_check](https://mymauticsite/s/saml/login_check) I get a 302 found however it redirects after that to [https://mymauticsite/s/login](https://mymauticsite/s/login) with error message saying - Invalid login. Please verify credentials.

These errors are showing in the log: Nada, absolutely nothing. I am checking errors here: /var/www/mymauticfolder/var/logs. Is there any way to increase the debug level on the SSO logs? If yes which file to edit from where?

Steps I have tried to fix the problem:  
I have checked my Attributes mapping and in depth gone through the metadata xml file.  
All the attributes go through to my site that are necessary to create a new user upon first login. CORS is setup properly in apache.

Am I missing something special on the Azure side? I changed the nameID to send email address instead, but not sure if this helps?

See attached screenshot for error:

 ![Mautic Error](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/b/bedde1ed998514408c2d8c2d36e3dfafd29777e5.png)

---

<div class="post-metadata">

**Author:** ![jasjitchopra](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jasjitchopra](https://forum.mautic.org/u/jasjitchopra)\
**Post date:** [June 28, 2023, 10:44am UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/2 "2023-06-28T10:44:44Z")

</div>

Anyone got this working?

---

<div class="post-metadata">

**Author:** ![jasjitchopra](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jasjitchopra](https://forum.mautic.org/u/jasjitchopra)\
**Post date:** [June 30, 2023, 12:38pm UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/3 "2023-06-30T12:38:49Z")

</div>

I got this working using advice from here: [Microsoft SSO Integration - Solved](https://forum.mautic.org/t/microsoft-sso-integration-solved/21141)

So you have to use complete url for attributes as defined in the schema of the metadata xml.

For email I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)  
For Frist Name I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname)  
For Last Name I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname)  
And since I tend to configure usernames as email (personal choice) I used this fro Username which is optional: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)

You define these settings in the Mautic SAML SSO Settings page

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/1X/43c63600fe51440378769136903f1fa2a9a34102.png) [@system](https://forum.mautic.org/u/system)\
**Post date:** [July 2, 2023, 12:38am UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/4 "2023-07-02T00:38:50Z")

</div>

This topic was automatically closed 36 hours after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [July 3, 2023, 8:12am UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/5 "2023-07-03T08:12:07Z")

</div>

@jasjitchopra would you be open to making an update to our documentation to make this clear for people in the future?

If you go to this page: [Authentication — Mautic Documentation 0.1 documentation](https://mautic-documentation.readthedocs.io/en/latest/authentication/authentication.html) you could add a section at the bottom for Azure-specific settings.

There’s an ‘edit on GitHub’ button top right of the page which takes you directly to the page you need to edit, then you can click the pencil button to suggest changes.

Happy to help you get started if you’d like to contribute this information to help others!
