Overview
This article helps you troubleshoot common SAML login issues and explains what happens when SAML single sign-on (SSO) is disabled for your Auvik tenant.
Before Disabling SAML
If users are having trouble signing in with SAML, the issue may be related to your identity provider configuration rather than the SAML configuration in Auvik.
One common cause is a mismatch between the email address sent by your identity provider and the email address associated with the user's Auvik account.
For example, users may have multiple email aliases configured in Microsoft Entra ID. For SAML authentication to work correctly, the email address sent to Auvik must match the email address registered for the user in Auvik.
If you use Microsoft Entra ID, review Configuring Auvik single sign-on with Azure AD.
Correcting the user attribute configuration may resolve the sign-in issue without requiring SAML to be disabled.
How SAML Login Works
When you enter your email address on the Auvik login page and select Next, Auvik determines which authentication method is associated with your account.
If your account is configured to use SAML, your browser is redirected to your organization's identity provider, such as Microsoft Entra ID or Okta. You complete authentication with your identity provider before being redirected back to Auvik.
A SAML login can also be initiated directly from your identity provider.
What happens after you're redirected?
After your browser is redirected to your identity provider, authentication occurs outside of Auvik. Auvik receives information about the login when your identity provider sends you back to Auvik.
If the login fails before you're returned to Auvik, information about the failure may only be available from your identity provider.
Both your identity provider and your Auvik tenant must be configured correctly for the SAML login to succeed.
Note: SAML login can also be initiated directly from your identity provider. If authentication fails before you're returned to Auvik, troubleshooting information, such as authentication logs or error details, may only be available from your identity provider.
Common SAML Login Errors
For a SAML login to succeed, both your identity provider and your Auvik tenant must be configured correctly.
The following sections describe common SAML login scenarios:
1. You Are Not Authorized(Assigned) Access to Auvik
Many identity providers require an administrator to explicitly assign users access to individual applications.
If you aren't assigned access to Auvik, your identity provider may prevent you from completing the login.
Ensure
- You're assigned access to the Auvik application.
- Your account is permitted to use the application.
- The correct user information is being sent to Auvik.
2. Your Identity Provider Displays an Error
You may be redirected to your identity provider but receive an error before you're returned to Auvik.
For example, Okta may display a message such as:
400 - Your request resulted in an error.
This typically means the error occurred during authentication with your identity provider.
3. You Have Not Been Invited to Auvik
If you see this error message, SAML is configured correctly for your organization, but one of the following may apply:
- You haven't been invited to Auvik.
- You have an existing Auvik account, but it hasn't yet been migrated to use SAML. In this case, sign in using your existing authentication method, such as your Auvik password or OAuth.
If you're still unable to sign in after trying the appropriate authentication method, contact Auvik Support for assistance.
What Happens When SAML Is Disabled
Once the SAML configuration has been successfully removed from the tenant, affected users are migrated back to password-based authentication.
Disabling SAML triggers password reset notifications for the affected users. Because these users were previously authenticating through SSO, they must complete the password reset process and create a password before they can access Auvik again.
Removing the SAML configuration does not mean users can immediately sign in with their previous SSO credentials.
What to Do After SAML Is Disabled
If your account previously used SAML:
- Check your inbox for a password reset or account recovery email from Auvik.
- Open the email and select the account recovery link.
- Follow the instructions to create a new password.
- Return to the Auvik login page.
- Enter the email address associated with your Auvik account.
- Sign in using your new password.
Each affected user must complete the password reset process before they can access Auvik again.
Important: If a new password reset email is requested, use the link in the most recent email. An older recovery link may no longer be valid.
What to Do If Your Account Recovery Link Has Expired
A user may encounter an error indicating that the account recovery link has expired.
For example:
You have accessed an account recovery link that has expired.
When this occurs, the user cannot complete the password setup using that recovery link.
Contact Auvik Support for assistance.
Troubleshooting Checklist
Before requesting that SAML be disabled, confirm the following:
- You're entering the email address associated with your Auvik account.
- You've been invited to the correct Auvik tenant.
- Your account is configured to use SAML.
- Your identity provider has assigned you access to the Auvik application.
- The email address sent by your identity provider matches the email address registered in Auvik.
If you've completed these checks and are still unable to sign in, contact Auvik Support.
Information Required to Escalate to Auvik Support
To help Auvik Support investigate the issue, provide the following:
- Affected site - The Auvik site where the login issue is occurring.
- Affected user - The email address of the user experiencing the issue.
- SAML trace - Capture and share a SAML trace while reproducing the login issue. SAML-tracer identifies requests containing SAML payloads and extracts information that can help diagnose authentication and configuration issues.
Providing this information with your support request can help with investigating the SAML login issue.
Reference articles:
Resolving common issues with Auvik SSO and Microsoft Entra ID
Configuring Auvik single sign-on with Azure AD
