When user logs in using SAML, they face 403 access denied error. We checked the users ID and they have the required access levels. When checked on tomcat-stdout logs we see the following issue 'Cannot request SAML Assertion for SBAF Authorize Click since user is not valid for SBAF'. Any leads on this?
Discussion posts and replies are publicly visible
Run a SAML Trace, capture exactly what the IdP is sending. The KB article KB-1450 specifically covers how to gather a SAML trace to identify the Appian username shown in the SAML assertion — this will tell you definitively what value SBAF is trying to validate against. Appian