/ /

Troubleshooting SSO and authentication issues

Diagnose and resolve SSO and authentication issues
Updated 10 hours ago

Troubleshooting SSO and authentication issues

1. IdP rejects the Responsive app because the Entity ID already exists

Symptoms

When configuring SAML SSO for more than one Responsive environment (for example, production and sandbox) under the same identity provider (IdP), the IdP rejects the second app or its metadata because the Entity ID (Audience URI) is already in use.

Cause
SAML requires each Entity ID to be unique within an IdP directory. By default, Responsive environments (production and sandbox) share the same Entity ID (Audience URI), so registering a second environment in the same directory creates a duplicate that the IdP blocks.

Resolution
Contact Responsive Support and request a unique Entity ID for the specific environment (production or sandbox). Support provides the value for that instance. Enter it in the Entity ID (Audience URI) field of your IdP configuration for that environment, then save and retry.

2. Okta users get a "Missing Data" error after login

Symptoms

After signing in through Okta, users are not taken to their Responsive workspace. Instead, they land on an error page showing Missing Data - Go to login, and the browser URL includes /v2/saml-callback#error=Missing+Data. Clicking Go to login sometimes lets them through on a second attempt, but the error keeps recurring.

Cause

The SAML sign-in itself succeeds, but the assertion coming from Okta is missing the value that tells Responsive which organization the user belongs to. This value is carried by the Default Relay State in the Okta application. If the Default Relay State is blank or incorrect, Responsive validates the user's identity but cannot route them to the correct account, so it stops with the Missing Data error.

Resolution

In your Okta admin console, open the Responsive SAML application and confirm these settings:

Okta SAML setting

Value

Application type

SAML 2.0

Single sign-on URL (ACS)

Your Responsive region URL (as shown in the Okta SAML configuration article)

Entity ID (Audience URI)

Matches your Responsive SAML metadata

Default Relay State

The Default Relay State value from Responsive

To get the correct Default Relay State value, in Responsive go to Organization Settings > My Organization > Security > SSO/SCIM > SSO and copy the Default Relay State shown there. Paste it into the Default Relay State field in Okta and click Save.

Once the Default Relay State is set correctly, the Missing Data error clears. For full setup steps, see the Okta SAML configuration article.

3. Users get an "Assigned Access" error during login

Symptoms

A user attempts to log in via Azure SSO and sees "Your administrator has configured the Application RFPIO to block users unless they are specifically granted 'assigned' access to the application".

Cause

The Assignment Required property is enabled in the Azure Enterprise Application settings for Responsive, but the specific user has not been added to the application's user list.

Resolution

  1. In the Azure Portal, navigate to Microsoft Entra ID > Enterprise Applications.

  2. Search for and select the RFPIO/Responsive application.

  3. From the left sidebar, select Users and groups.

  4. Click Add user/group and assign the affected user to the application.

  5. Alternatively, if you want all users in your directory to have access without manual assignment, go to Properties and set Assignment required? to No.

Note: This configuration must be managed within the Azure portal; it cannot be changed from within Responsive.

Was this article helpful?
Subscribe to receive updates on this article