<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-1686 "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-1686 "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider</link><pubDate>Thu, 30 Aug 2018 17:25:10 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Current Revision posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 5:25:10 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/3264.Untitled.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-11/3264.Untitled.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one supported by&amp;nbsp;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/1</link><pubDate>Thu, 30 Aug 2018 19:36:03 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jussi Lundstedt</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Jussi Lundstedt on 8/30/2018 7:36:03 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, which is &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;not supported&lt;/a&gt; by Azure AD as of August 2018.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &amp;quot;Authentication Method&amp;quot; to None, and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This has the impact of&amp;nbsp;having AzureAD use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the AuthnContextClassRef value, as this is the only one supported by Azure AD.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-1686 "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/10</link><pubDate>Thu, 30 Aug 2018 17:24:24 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 10 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 5:24:24 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-11/Untitled.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-11/Untitled.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one supported by&amp;nbsp;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-1686 "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/9</link><pubDate>Thu, 30 Aug 2018 17:23:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 9 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 5:23:58 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-11/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one supported by&amp;nbsp;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-1686 "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/8</link><pubDate>Thu, 30 Aug 2018 17:20:53 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 8 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 5:20:53 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one supported by&amp;nbsp;&lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/7</link><pubDate>Thu, 30 Aug 2018 17:02:36 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jussi Lundstedt</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 7 posted to Appian Knowledge Base by Jussi Lundstedt on 8/30/2018 5:02:36 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/6</link><pubDate>Thu, 30 Aug 2018 16:59:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jussi Lundstedt</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 6 posted to Appian Knowledge Base by Jussi Lundstedt on 8/30/2018 4:59:52 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This prompts AzureAD to use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/5</link><pubDate>Thu, 30 Aug 2018 16:48:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 5 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 4:48:30 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This has the impact of&amp;nbsp;having AzureAD use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/4</link><pubDate>Thu, 30 Aug 2018 16:47:53 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 4 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 4:47:53 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x0/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This has the impact of&amp;nbsp;having AzureAD use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/3</link><pubDate>Thu, 30 Aug 2018 16:46:29 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jordan Horwat</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 3 posted to Appian Knowledge Base by Jordan Horwat on 8/30/2018 4:46:29 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &lt;strong&gt;Authentication Method&lt;/strong&gt; to &lt;strong&gt;None&lt;/strong&gt;&amp;nbsp;and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This has the impact of&amp;nbsp;having AzureAD use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, authentication, ADFS&lt;/div&gt;
</description></item><item><title>KB-XXXX "SAML authentication request's RequestedAuthenticationContext's Comparison value must be 'Exact'" error thrown when using Microsoft Azure AD as a SAML Identity Provider</title><link>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider/revision/2</link><pubDate>Thu, 30 Aug 2018 15:39:01 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2ee55f46-4c5d-4799-9260-857f1735dd63</guid><dc:creator>Jussi Lundstedt</dc:creator><comments>https://community.appian.com/support/w/kb/1109/kb-1686-saml-authentication-request-s-requestedauthenticationcontext-s-comparison-value-must-be-exact-error-thrown-when-using-microsoft-azure-ad-as-a-saml-identity-provider#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Jussi Lundstedt on 8/30/2018 3:39:01 PM&lt;br /&gt;
&lt;h2&gt;Symptoms&lt;/h2&gt;
&lt;p&gt;When&amp;nbsp;setting up a new SAML configuration using Microsoft Azure AD as the SAML Identity Provider, the following error is thrown when authenticating:&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_18_2D00_39.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;pre&gt;AADSTS90023: SAML authentication request&amp;#39;s RequestedAuthenticationContext&amp;#39;s Comparison value must be &amp;quot;Exact&amp;quot;&lt;/pre&gt;
&lt;h2&gt;Cause&lt;/h2&gt;
&lt;p&gt;Appian uses a&amp;nbsp;&lt;code&gt;RequestedAuthnContext&lt;/code&gt; comparison type of &lt;code&gt;minimum&lt;/code&gt;, while Azure AD requires Service Providers to use&amp;nbsp;&lt;code&gt;exact&lt;/code&gt;, which is not supported by Appian.&lt;/p&gt;
&lt;h2&gt;Action&lt;/h2&gt;
&lt;p&gt;In Appian&amp;#39;s SAML settings located in the Appian Administration Console, set the value for &amp;quot;Authentication Method&amp;quot; to None, and retest the authentication.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png"&gt;&lt;img src="/resized-image/__size/1200x240/__key/communityserver-wikis-components-files/00-00-00-00-13/chrome_5F00_2018_2D00_08_2D00_30_5F00_15_2D00_26_2D00_28.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This has the impact of&amp;nbsp;having AzureAD use &lt;code&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/code&gt; as the &lt;code&gt;AuthnContextClassRef&lt;/code&gt; value, as this is the only one &lt;a href="https://docs.microsoft.com/en-us/azure/active-directory/develop/single-sign-on-saml-protocol#requestauthncontext" target="_blank"&gt;supported by Azure AD&lt;/a&gt;&amp;nbsp;as of August 2018.&lt;/p&gt;
&lt;h2&gt;Affected Versions&lt;/h2&gt;
&lt;p&gt;This article applies to Appian version 7.11 and later.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2018.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, authentication, ADFS&lt;/div&gt;
</description></item></channel></rss>