After completing all the documented steps and deleting and retrying the app configuration in Azure a few times, we still get this error when trying to configure SSO: Browser error we get after clicking login and getting redirected from the login window:
This sts.windows.net page can't be foundNo webpage was found for the web address: https://sts.windows.net/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxxx?SAMLRequest=buaZHXoirzCQAsIdFm3ZLveZOnjKkuE1UOvZRlNWM1Ex0rKtlkkE8yxFFtLAawoSV5mjOaVjRt9lnFWclZExfl7BuJtpeEPkxOzslfi1O8iJB%2F3O%2B3dPtltyfR19cGJwG59MXPdP%2B%2BqOuL4bUdsrjSxWlR8j%2BJz5P3Nt6O6PPE3ay3zmj5O1oZ4443XkFQLQl%2BVCS6dX6A8G%2BnWZydX3RH%2B7OUqwG0WXWdV4gkWVy4f5%2Fr4g8%3D&RelayState=4b117eed-5515-4880-9131-32c2f36b7a91HTTP ERROR 404
Any insights into the connection error?
Hi @Minh Tran
It appears there may be a configuration issue, likely related to the ACS URL configuration.
To resolve this, you'll need to collect the SAML metadata from both the Atlassian Access and Azure AD and configure them accordingly.
For detailed guidance on the setup, you can refer to the following document:
https://support.atlassian.com/provisioning-users/docs/connect-to-azure-active-directory/
https://learn.microsoft.com/en-us/entra/identity/saas-apps/atlassian-cloud-tutorial
As an SSO vendor, we have created an extensive setup guide for configuring SAML SSO with Azure AD for our Data Center app. You can refer to its Azure AD configuration as well.
https://www.miniorange.com/atlassian/saml-single-sign-on-sso-jira-using-azure-ad-idp?version=2.0.0
Thanks for your reply - This is for Atlassian Cloud and we have followed the instructions in both those links you provided (although we are not setting up provisioning just yet, just SSO). We've repeated the steps multiple times and deleted the app and restarted without success. After double and triple checking that we copied the contents to and from Azure AD and Atlassian SAML set up correctly, we continue to run into the 404 error.
Hello @Minh Tran ,
Welcome to Atlassian Community!
In order to solve this issue you just need to swap the values Identity Provider Entity ID and Identity Provider SSO URL in your SAML configuration.
Regards,
Thanks!
Clearly I am a novice at this. Thanks for the assist @Hector Menchaca . Just raced through the instructions and did not follow them closely enough. Assumed the order they provided was the order to enter them in the SAML set up.
I am running into the exact same error. When I switched these as you suggest, I run into a new error: AADSTS900023: Specified tenant identifier 'REDACTED' is neither a valid DNS name, nor a valid external domain.
If you have any quick tips, I'd love to know!
Hello @jessica_huebner ,
Thanks for your reply.!
Can you let me know what is the flow you are following in order to get this error? When you switched the values on your SAML configuration and you trying to login you are getting this error?
Below are the steps I followed:
Doing this gave me the same error as what Minh posted above (exception of course is our unique ID). Then, when I tried switching the values as you suggested, so that the Microsoft Entra Identifier was in the SSO URL field and Login URL was in the Entity ID field in the SAML config. The user got a different error: AADSTS900023: Specified tenant identifier...
I appreciate any guidance you may be able to provide!
It looks like you're new here. Sign in or register to get started.