Authentication to My Company Portal via SSO Application
-
Friday, September 04, 2009 9:13 AMHi,
I have a user that has the SSO Application installed. When he logs in, it authenticates him and he can then see the My Company Portal link in the SSO Application. When he clicks on the link it opens up ie and then you see the standard Download SSO/Login to Portal dialogue box as if the SSO Application was not being used. Looking in the logs I can see the SSO Application is opening https://home.microsoftonline.com/CertPages/CertLogin.aspx however the certificate login seems to fail and he is presented with https://home.microsoftonline.com/Default.aspx?ReturnUrl=/Home/Home.aspx in IE. I have tried deleting the Certificate and have seen the SSO Application create a new one however it still fails. There is no other information in the SSO log after has sent the open IE request.
The user is in EMEA, the SharePoint online is in NOAM. All other users are unaffected by this issue and it does not appear to be PC related as we have tested using a different PC that works for other users. He has a Roaming Profile so there may be something in there that is not helping.
Any ideas on how to resolve this are most welcome.
Regards,
Martin
Answers
-
Monday, October 12, 2009 9:12 PMOwner
Hey Martin,
We are sorry that you are still facing the issue. Everything you had pointed out indicates to the bug I talked about. If the affected users launch the Url (https://home.noam.microsoftonline.com/Default.aspx?ReturnUrl=/Home/Home.aspx), does it work? This is the fix we are going to apply. This will be done in a few days from now.
I will update the thread once we apply the fixes on our end. If it persists after that too, we will investigate furthere.
regards,
Vijay- Marked As Answer by Lynn Rickard [MSFT]Moderator Friday, October 16, 2009 1:34 AM
All Replies
-
Tuesday, September 08, 2009 8:33 PMModerator
Could you copy paste the log file? Set the "Enable data logging for trouble shooting" check box through Options tab- Advanced options.
Also, please exit the sso client (right click on sso client icon from the sys tray and click on Exit menu), before setting the above option. -
Tuesday, September 08, 2009 9:23 PMOwnerThis is actually a bug in our server. If your account is in the US datacenter, the server is returning the global URL for company portal, instead of the US specific one. So, if you are outside of the US, the global load balancers redirect you to the company portal in the nearest datacenter.
We will address this issue soon and will let you know.- Marked As Answer by Nagarajan Raju [MSFT]Moderator Tuesday, September 15, 2009 2:31 AM
- Unmarked As Answer by tliving Tuesday, September 29, 2009 11:00 AM
- Marked As Answer by Lynn Rickard [MSFT]Moderator Thursday, October 01, 2009 2:27 AM
- Unmarked As Answer by tliving Friday, October 02, 2009 8:09 AM
-
Tuesday, September 15, 2009 8:47 AMVijay,
Thanks for the input, however this is not the general bug for users in EMEA, I have a support case open for that one and when you are affected by that issue our EU users get a Service Unavalable message, however if they input "noam." in the url they are directed to the portal without requiring any further authentication. In this particular users case it appears that the certificate is not being recognised for authentication at all and he keeps getting prompted for the username and password. My machine works fine, if this users credentials are put into the SSO Application on my machine with me logged into windows it works as we expect with the known EMEA redirect issue. If the user logs onto my machine as himself then the certificate is created however not recognised, the problem appears to be in his Roaming Profile, any ideas what this could be?
Update 18/9/9:
We have found two more users with the same problem who do not have Roaming Profiles, we may have more users with the problem who are not coming forward because they belive it is working as they input user id and get in. When they log onto my machine they work as expected so it is definately a profile related issue
Regards,
Martin -
Tuesday, September 29, 2009 11:01 AMHi,
This is still a problem. Can anyone help please?
Martin -
Friday, October 02, 2009 8:13 AMHi,
I have again marked this as unanswered - Please read the thread! This is not the same problem as mentioned by Vijay. I am fully aware of that issue and this is not it. It is not to do with the redirect it is to do with the certificate not being recognised for authentication.
Regards,
Martin -
Monday, October 12, 2009 9:12 PMOwner
Hey Martin,
We are sorry that you are still facing the issue. Everything you had pointed out indicates to the bug I talked about. If the affected users launch the Url (https://home.noam.microsoftonline.com/Default.aspx?ReturnUrl=/Home/Home.aspx), does it work? This is the fix we are going to apply. This will be done in a few days from now.
I will update the thread once we apply the fixes on our end. If it persists after that too, we will investigate furthere.
regards,
Vijay- Marked As Answer by Lynn Rickard [MSFT]Moderator Friday, October 16, 2009 1:34 AM
-
Thursday, October 22, 2009 3:22 PMI too am experiencing the exact situation tliving describes above. I have exhausted the first tier of MS Online tech support. Any updates on this?
Also, when enabling data logging in the Microsoft Online Services Signon client, where do the log files get written to? Can't find them to troubleshoot with.

