# SSO - Invalid inbound message destination

**URL:** <https://forum.mautic.org/t/sso-invalid-inbound-message-destination/23859>\
**Category:** Product Support\
**Created:** [April 23, 2022, 7:34pm UTC](https://forum.mautic.org/t/sso-invalid-inbound-message-destination/23859 "2022-04-23T19:34:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ilo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ilo/32/1181_2.png) [@ilo](https://forum.mautic.org/u/ilo)\
**Post date:** [April 23, 2022, 7:34pm UTC](https://forum.mautic.org/t/sso-invalid-inbound-message-destination/23859/1 "2022-04-23T19:34:47Z")

</div>

**Your software**  
My Mautic version is: 4.2.1 Mautic docker container behind an IIS server with reverse proxy and SSO via Azure.

**Your problem**  
My problem is:

when redirected to /s/saml/login\_check, there is this error :  
Invalid inbound message destination “[https://xxxxx/s/saml/login\_check](https://xxxxx/s/saml/login_check)”

Steps I have tried to fix the problem:

- set trusted proxy
- followed the advice from here [Invalid inbound message destination · Issue #58 · lightSAML/SpBundle · GitHub](https://github.com/lightSAML/SpBundle/issues/58) and added a new AssertionConsumerService with the local url reverse proxy

---

<div class="post-metadata">

**Author:** ![pierre\_a](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/pierre_a/32/7031_2.png) [@pierre\_a](https://forum.mautic.org/u/pierre_a)\
**Post date:** [April 25, 2022, 4:11pm UTC](https://forum.mautic.org/t/sso-invalid-inbound-message-destination/23859/2 "2022-04-25T16:11:29Z")

</div>

Hello @ilo,

Can you tell us who prepared this Docker image?  
Were you able to isolate the elements related to your technical environment (firewall, Azure hosting, IIS server, etc.)? To make sure that this is not what is blocking?

I suggest you install a test instance on a LAMP environment via Composer and check if you get the same error message. It is essential to make sure that the blocking point is on the Mautic side and not on your environment side.

What do you think?

Pierre

---

<div class="post-metadata">

**Author:** ![ilo](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ilo/32/1181_2.png) [@ilo](https://forum.mautic.org/u/ilo)\
**Post date:** [April 26, 2022, 5:07am UTC](https://forum.mautic.org/t/sso-invalid-inbound-message-destination/23859/3 "2022-04-26T05:07:29Z")

</div>

Hi @pierre_a,

Thank you for your reply. I’m using the last available version of docker-mautic.  
I’ve finally figured out the problem. I was implementing the solution from the link I’ve sent, but, instead of adding a new AssertionConsumerService with the local url of the reverse proxy, I should have added the public url, as, by default, it seems that the location was set with the reverse proxy url.
