IDP Specific

Why do I get a “SAML Response Status: urn:oasis:names:tc:SAML:2.0:status:Responder” error during Azure AD login?

5 views 0

Probable Cause:

The Reply URL (Assertion Consumer Service URL) configured in Azure AD does not exactly match the ACS URL provided by the miniOrange plugin.

Solution:

  1. In the miniOrange SAML SSO plugin, go to Service Provider Metadata and copy the ACS URL (Assertion Consumer Service URL). Also note the SP Entity ID/Issuer.
  2. In Azure Portal, open: Microsoft Entra ID → Enterprise Applications → [Your SAML app] → Single sign-on → SAML.
  3. Under Basic SAML Configuration, verify:
    • Reply URL (ACS URL) matches the plugin ACS URL exactly (https, domain, path, case, and trailing slash).
    • Identifier (Entity ID) matches the plugin SP Entity ID/Issuer.
  4. Click Save.
  5. Clear cache (browser/WordPress/CDN if used) and re-test SSO.

Note: If you have multiple environments (staging/prod), make sure the Reply URL and Identifier values are set for the correct environment you’re testing.

Still need help?

Contact us at samlsupport@xecurify.com

Was this helpful?


Hello there!

Need Help? We are right here!

support