AADSTS500089: SAML 2.0 assertion validation failed: SAML token is invalid.

lifonghsu 31 Reputation points
2020-04-24T11:32:29.903+00:00

I used a custom SAML IDP to federate, but I always get the error code.

Request Id: 2d40239e-635d-48af-9ca0-437f7a5c2900

Correlation Id: 17b56a5c-c043-40e1-af60-fba489f32ff6

Timestamp: 2020-04-24T11:19:51Z

Message: AADSTS500089: SAML 2.0 assertion validation failed: SAML token is invalid.

can anyone help

Thanks

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,471 questions
0 comments No comments
{count} votes

Accepted answer
  1. soumi-MSFT 11,716 Reputation points Microsoft Employee
    2020-04-24T12:22:08.223+00:00

    @lifonghsu , This error states that the key algorithm of the certificate used is not supported. It seems, somehow the the certificate being used to SAML request to AAD is not liked by AAD and hence AAD is throwing this error.

    To help you further, it would be great if you can share some more details on this app and may be screenshots of your configuration for us to understand this in a better way.

    Hope this helps.

    Do let us know if this helps and if there are any more queries around this, please do let us know so that we can help you further. Also, please do not forget to accept the response as Answer; if the above response helped in answering your query.


1 additional answer

Sort by: Most helpful
  1. Naveen 1 Reputation point
    2021-03-15T06:07:01.953+00:00

    @lifonghsu I am also facing same issue, is that issue resolved for you?

    @soumi-MSFT i tried with slef signed certificate with both SHA1 and SHA256 algorthim . getting SAME error.

    0 comments No comments