Symptoms
- After redirection from the external Identity Provider (IdP) to the Workspace, a 401 Unauthorized message is shown.
- In the appliance's log files, this error message can be seen: Unable to get username from SAML response.
Cause
Possible causes:
- An incorrect username claim was specified.
- An incorrect configuration of the claim issuance on the external Identity Provider (IdP).
Resolution
- Verify the configuration of the claims on the external IdP.
- When using Active Directory Federation Services (ADFS), check Using Microsoft Active Directory Federation Services to sign in to Parallels Secure Workspace (SAML) .
- Verify the username claim in Parallels Secure Workspace, configured under System Settings > Configure > User Connector: Federated Authentication.
- Default:
- For Microsoft ADFS: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn
- For Azure: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- Default:
Was this article helpful?
Tell us how we can improve it.