<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSO with Azure Active Directory : Authentication failed in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/sso-with-azure-active-directory-authentication-failed/m-p/39445#M305</link>
    <description>&lt;P&gt;I have a Databricks account with the E2 version of the Databricks platform. The unified login is not enabled on the account because it was created before June 21, 2023.&lt;/P&gt;&lt;P&gt;I configured SSO authentication for the account and for a given workspace (separately). Both configurations use the same identity provider at the account level and at the workspace level. The identity provider is an Azure Active Directory tenant.&lt;/P&gt;&lt;P&gt;The SSO account level configuration use the OpenID Connect (OIDC) protocol as it is recommended by the documentation. &lt;A href="https://docs.databricks.com/en/administration-guide/account-settings-e2/single-sign-on/azure-ad.html" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/account-settings-e2/single-sign-on/azure-ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The SSO workspace level configuration use the SAML protocol. &lt;A href="https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/azure-ad.html" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/azure-ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The &lt;EM&gt;Allow auto user creation &lt;/EM&gt;and &lt;EM&gt;Allow IAM role entitlement auto sync&lt;/EM&gt; features are not activated.&lt;/P&gt;&lt;P&gt;The &lt;EM&gt;SCIM provisioning&lt;/EM&gt; feature is not activated. We want to have a successful authentication before activating it.&lt;/P&gt;&lt;P&gt;We followed every step of the documentation but we still receive the following error message : &lt;STRONG&gt;Single Sign-On authentication failed&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We verified every configuration values and read the &lt;EM&gt;Troubleshooting&lt;/EM&gt; section of the documentation. &lt;A href="https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/index.html#troubleshooting" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/index.html#troubleshooting&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I installed the SAML Tracer extension and analysed the SAML response. I seems that it is correctly signed. You can find it inside the file attached to this message.&lt;/P&gt;&lt;P&gt;Any help would be really appreciated,&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2023 13:16:05 GMT</pubDate>
    <dc:creator>fradetjulien</dc:creator>
    <dc:date>2023-08-09T13:16:05Z</dc:date>
    <item>
      <title>SSO with Azure Active Directory : Authentication failed</title>
      <link>https://community.databricks.com/t5/administration-architecture/sso-with-azure-active-directory-authentication-failed/m-p/39445#M305</link>
      <description>&lt;P&gt;I have a Databricks account with the E2 version of the Databricks platform. The unified login is not enabled on the account because it was created before June 21, 2023.&lt;/P&gt;&lt;P&gt;I configured SSO authentication for the account and for a given workspace (separately). Both configurations use the same identity provider at the account level and at the workspace level. The identity provider is an Azure Active Directory tenant.&lt;/P&gt;&lt;P&gt;The SSO account level configuration use the OpenID Connect (OIDC) protocol as it is recommended by the documentation. &lt;A href="https://docs.databricks.com/en/administration-guide/account-settings-e2/single-sign-on/azure-ad.html" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/account-settings-e2/single-sign-on/azure-ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The SSO workspace level configuration use the SAML protocol. &lt;A href="https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/azure-ad.html" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/azure-ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The &lt;EM&gt;Allow auto user creation &lt;/EM&gt;and &lt;EM&gt;Allow IAM role entitlement auto sync&lt;/EM&gt; features are not activated.&lt;/P&gt;&lt;P&gt;The &lt;EM&gt;SCIM provisioning&lt;/EM&gt; feature is not activated. We want to have a successful authentication before activating it.&lt;/P&gt;&lt;P&gt;We followed every step of the documentation but we still receive the following error message : &lt;STRONG&gt;Single Sign-On authentication failed&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We verified every configuration values and read the &lt;EM&gt;Troubleshooting&lt;/EM&gt; section of the documentation. &lt;A href="https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/index.html#troubleshooting" target="_blank" rel="noopener"&gt;https://docs.databricks.com/en/administration-guide/users-groups/single-sign-on/index.html#troubleshooting&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I installed the SAML Tracer extension and analysed the SAML response. I seems that it is correctly signed. You can find it inside the file attached to this message.&lt;/P&gt;&lt;P&gt;Any help would be really appreciated,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 13:16:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sso-with-azure-active-directory-authentication-failed/m-p/39445#M305</guid>
      <dc:creator>fradetjulien</dc:creator>
      <dc:date>2023-08-09T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSO with Azure Active Directory : Authentication failed</title>
      <link>https://community.databricks.com/t5/administration-architecture/sso-with-azure-active-directory-authentication-failed/m-p/62060#M929</link>
      <description>&lt;P&gt;where you able to resolve this? we too face same error&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 06:37:36 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/sso-with-azure-active-directory-authentication-failed/m-p/62060#M929</guid>
      <dc:creator>146404</dc:creator>
      <dc:date>2024-02-27T06:37:36Z</dc:date>
    </item>
  </channel>
</rss>

