<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2323 SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2323 SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in</link><pubDate>Mon, 23 Sep 2024 01:54:28 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>Maggie Deppe-Walker</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Current Revision posted to Appian Knowledge Base by Maggie Deppe-Walker on 9/23/2024 1:54:28 AM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Symptoms&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Existing users are unable to authenticate&amp;nbsp;with SAML&amp;nbsp;when&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;Group Membership Synchronization&lt;/a&gt;&amp;nbsp;is used to add users to the configured&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;However, SAML works for:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users configured with &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;create new users upon sign-in&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Users already in the configured&amp;nbsp;Authentication group.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following logging is observed for users that are unable to authenticate with Group Membership Synchronization:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;span&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;t&lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;omcat-access.log&lt;/strong&gt;:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;tomcat-stdOut.log&lt;/strong&gt;:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;/pre&gt;
&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;login-audit.csv&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Cause&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;When&amp;nbsp;the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on Group Membership Synchronization to put the user into the SAML group, authentication will fail because the user is not in the Authentication group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login when new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in will be able to log in successfully and see their group membership synced as they are in the Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Add users to the configured Authentication group prior to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Configure the&amp;nbsp;&lt;span&gt;Authentication group&amp;nbsp;to be&lt;/span&gt;&amp;nbsp;a standalone group that does not depend on&lt;span&gt;&amp;nbsp;Group Membership Synchronization&lt;/span&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Ensure the Authentication Group has a different &lt;a href="https://docs.appian.com/suite/help/latest/Group_Types.html"&gt;Group Type&lt;/a&gt;&amp;nbsp;than the&amp;nbsp;group used for &lt;span&gt;Group Membership Synchronization&lt;/span&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;A product use case has been logged to the Appian Product Team for consideration to add this functionality in the product for multiple IdP&amp;#39;s (#7032). Kindly note it is not Appian Support&amp;rsquo;s policy to disclose how or when a product use case will be implemented. Please &lt;a href="https://forum.appian.com/suite/sites/myappian/page/support"&gt;create a support case&lt;/a&gt; to request addition to this product enhancement request.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2024&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>KB-2323 SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/8</link><pubDate>Thu, 19 Sep 2024 04:47:16 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>Maggie Deppe-Walker</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 8 posted to Appian Knowledge Base by Maggie Deppe-Walker on 9/19/2024 4:47:16 AM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Symptoms&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Existing users are unable to authenticate&amp;nbsp;with SAML&amp;nbsp;when&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;Group Membership Synchronization&lt;/a&gt;&amp;nbsp;is used to add users to the configured&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;However, SAML works for:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users configured with &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;create new users upon sign-in&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Users already in the configured&amp;nbsp;Authentication group.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following logging is observed for users that are unable to authenticate with Group Membership Synchronization:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;span&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;t&lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;omcat-access.log&lt;/strong&gt;:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;tomcat-stdOut.log&lt;/strong&gt;:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;/pre&gt;
&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;login-audit.csv&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Cause&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;When&amp;nbsp;the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on Group Membership Synchronization to put the user into the SAML group, authentication will fail because the user is not in the Authentication group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login when new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in will be able to log in successfully and see their group membership synced as they are in the Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Add users to the configured Authentication group prior to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Configure the&amp;nbsp;&lt;span&gt;Authentication group&amp;nbsp;to be&lt;/span&gt;&amp;nbsp;a standalone group that does not depend on&lt;span&gt;&amp;nbsp;Group Membership Synchronization&lt;/span&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Ensure the Authentication Group has a different &lt;a href="https://docs.appian.com/suite/help/latest/Group_Types.html"&gt;Group Type&lt;/a&gt;&amp;nbsp;than the&amp;nbsp;group used for &lt;span&gt;Group Membership Synchronization&lt;/span&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;A product use case has been logged to the Appian Product Team for consideration to add this functionality in the product (#7032). Kindly note it is not Appian Support&amp;rsquo;s policy to disclose how or when a product use case will be implemented. Please &lt;a href="https://forum.appian.com/suite/sites/myappian/page/support"&gt;create a support case&lt;/a&gt; to request addition to this product enhancement request.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2024&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[SUPP-311 DRAFT KB] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/7</link><pubDate>Mon, 12 Aug 2024 02:05:21 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>Maggie Deppe-Walker</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 7 posted to Appian Knowledge Base by Maggie Deppe-Walker on 8/12/2024 2:05:21 AM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Symptoms&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Existing users are unable to authenticate&amp;nbsp;with SAML&amp;nbsp;when&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;Group Membership Synchronization&lt;/a&gt;&amp;nbsp;is used to add users to the configured&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;However, SAML works for:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users configured with &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;create new users upon sign-in&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Users already in the configured&amp;nbsp;Authentication group.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following logging is observed for users that are unable to authenticate with Group Membership Synchronization:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;span&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;t&lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;omcat-access.log&lt;/strong&gt;:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;tomcat-stdOut.log&lt;/strong&gt;:&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;/pre&gt;
&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&amp;lt;APPIAN_HOME&amp;gt;/logs/&lt;strong&gt;login-audit.csv&lt;/strong&gt;&lt;span&gt;:&lt;/span&gt;&lt;br /&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Cause&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;Authentication group&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;When&amp;nbsp;the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on Group Membership Synchronization to put the user into the SAML group, authentication will fail because the user is not in the Authentication group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login when new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in will be able to log in successfully and see their group membership synced as they are in the Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;"&gt;Action&lt;/span&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Add users to the configured Authentication group prior to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Configure the&amp;nbsp;&lt;span&gt;Authentication group&amp;nbsp;to be&lt;/span&gt;&amp;nbsp;a standalone group that does not depend on&lt;span&gt;&amp;nbsp;Group Membership Synchronization&lt;/span&gt;. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;Ensure the Authentication Group has a different &lt;a href="https://docs.appian.com/suite/help/latest/Group_Types.html"&gt;Group Type&lt;/a&gt;&amp;nbsp;than the&amp;nbsp;group used for &lt;span&gt;Group Membership Synchronization&lt;/span&gt;.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;A product use case has been logged to the Appian Product Team for consideration to add this functionality in the product (#7032). Kindly note it is not Appian Support&amp;rsquo;s policy to disclose how or when a product use case will be implemented. Please &lt;a href="https://forum.appian.com/suite/sites/myappian/page/support"&gt;create a support case&lt;/a&gt; to request addition to this product enhancement request.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian.&lt;/p&gt;
&lt;p&gt;Last Reviewed: August 2024&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[SUPP-311 DRAFT KB] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/6</link><pubDate>Mon, 29 Jul 2024 23:40:15 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 6 posted to Appian Knowledge Base by camille.savagehansen on 7/29/2024 11:40:15 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;Users are unable to authenticate through SAML when adding users to the SAML Authentication group through&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt; SAML Group Membership Sync&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Symptom&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;SAML works for new users configured with &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create New User on Sign In&lt;/a&gt;&amp;rdquo;, and users already in the SAML Authentication group, but for users being added to the SAML group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;&amp;ldquo;Group Membership Sync&amp;rdquo;&lt;/a&gt; feature, SAML authentication fails and the user is not signed in.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;User is not signed in as confirmed in logging:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Tomcat-access.log:&amp;nbsp;&lt;br /&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Tomcat-stdOut.log:&lt;br /&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Login-audit.log&lt;br /&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;b&gt;&lt;span style="font-size:150%;"&gt;Cause&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;SAML Authentication group,&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;In design scenarios, where the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on the group membership sync to put the user into the SAML group, authentication will fail. This is because the user will not be in the Authentication SAML Group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login as new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in, will be able to login and see their group membership synced as they are in the SAML Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Adding Users to the SAML Authentication Group will allow the users to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt; SAML Authentication Group&lt;/a&gt; should be a standalone group that does not depend on the group membership sync. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The SAML Authentication Group should have a Different &lt;a href="https://docs.appian.com/suite/help/24.2/Group_Types.html"&gt;Group Type&lt;/a&gt; then the one used for membership sync.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you are impacted by this behaviour, and wish to record your desire for this feature to be enhanced in further released of Appian, please work with Appian Support, or your Account Executive, to share your product use case through Product Enhancement Request: &lt;em&gt;#7032 - Group membership sync for multiple IdP providers.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you have further questions, please reach out to Appian Support through a Support Case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-311] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/5</link><pubDate>Mon, 29 Jul 2024 23:24:27 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 5 posted to Appian Knowledge Base by camille.savagehansen on 7/29/2024 11:24:27 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;Users are unable to authenticate through SAML when adding users to the SAML Authentication group through&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt; SAML Group Membership Sync&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Symptom&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;SAML works for new users configured with &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create New User on Sign In&lt;/a&gt;&amp;rdquo;, and users already in the SAML Authentication group, but for users being added to the SAML group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;&amp;ldquo;Group Membership Sync&amp;rdquo;&lt;/a&gt; feature, SAML authentication fails and the user is not signed in.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;User is not signed in as confirmed in logging:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Tomcat-access.log:&amp;nbsp;&lt;br /&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Tomcat-stdOut.log:&lt;br /&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Login-audit.log&lt;br /&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;b&gt;&lt;span style="font-size:150%;"&gt;Cause&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;SAML Authentication group,&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;In design scenarios, where the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on the group membership sync to put the user into the SAML group, authentication will fail. This is because the user will not be in the Authentication SAML Group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login as new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in, will be able to login and see their group membership synced as they are in the SAML Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Adding Users to the SAML Authentication Group will allow the users to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt; SAML Authentication Group&lt;/a&gt; should be a standalone group that does not depend on the group membership sync. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The SAML Authentication Group should have a Different &lt;a href="https://docs.appian.com/suite/help/24.2/Group_Types.html"&gt;Group Type&lt;/a&gt; then the one used for membership sync.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you are impacted by this behaviour, and wish to record your desire for this feature to be enhanced in further released of Appian, please work with Appian Support, or your Account Executive, to share your product use case through Product Enhancement Request: &lt;em&gt;#7032 - Group membership sync for multiple IdP providers.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you have further questions, please reach out to Appian Support through a Support Case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-311] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/4</link><pubDate>Mon, 29 Jul 2024 23:24:07 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 4 posted to Appian Knowledge Base by camille.savagehansen on 7/29/2024 11:24:07 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;Users are unable to authenticate through SAML when adding users to the SAML Authentication group through&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt; SAML Group Membership Sync&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Symptom&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;SAML works for new users configured with &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create New User on Sign In&lt;/a&gt;&amp;rdquo;, and users already in the SAML Authentication group, but for users being added to the SAML group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;&amp;ldquo;Group Membership Sync&amp;rdquo;&lt;/a&gt; feature, SAML authentication fails and the user is not signed in.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;User is not signed in as confirmed in logging:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Tomcat-access.log:&amp;nbsp;&lt;br /&gt;&lt;code&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/code&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Tomcat-stdOut.log:&lt;br /&gt;&lt;code&gt;INFO&amp;nbsp; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;br /&gt;org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/code&gt;&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Login-audit.log&lt;br /&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;,Failed &amp;hellip;&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;b&gt;&lt;span style="font-size:150%;"&gt;Cause&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;SAML Authentication group,&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;In design scenarios, where the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on the group membership sync to put the user into the SAML group, authentication will fail. This is because the user will not be in the Authentication SAML Group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login as new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in, will be able to login and see their group membership synced as they are in the SAML Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Adding Users to the SAML Authentication Group will allow the users to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt; SAML Authentication Group&lt;/a&gt; should be a standalone group that does not depend on the group membership sync. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The SAML Authentication Group should have a Different &lt;a href="https://docs.appian.com/suite/help/24.2/Group_Types.html"&gt;Group Type&lt;/a&gt; then the one used for membership sync.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you are impacted by this behaviour, and wish to record your desire for this feature to be enhanced in further released of Appiah, please work with Appian Support, or your Account Executive, to share your product use case through Product Enhancement Request: &lt;em&gt;#7032 - Group membership sync for multiple IdP providers.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you have further questions, please reach out to Appian Support through a Support Case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-311] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/3</link><pubDate>Mon, 29 Jul 2024 23:09:55 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 3 posted to Appian Knowledge Base by camille.savagehansen on 7/29/2024 11:09:55 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;Users are unable to authenticate through SAML when adding users to the SAML Authentication group through&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt; SAML Group Membership Sync&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Symptom&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;SAML works for new users configured with &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create New User on Sign In&lt;/a&gt;&amp;rdquo;, and users already in the SAML Authentication group, but for users being added to the SAML group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;&amp;ldquo;Group Membership Sync&amp;rdquo;&lt;/a&gt; feature, SAML authentication fails and the user is not signed in.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;User is not signed in as confirmed in logging:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Tomcat-access.log:&amp;nbsp;&lt;br /&gt;&lt;/span&gt;&lt;pre class="ui-code" data-mode="text"&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;Tomcat-stdOut.log:&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;INFO&amp;#160; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken
org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;Login-audit.log&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;&amp;lt;USERNAME&amp;gt;,Failed …&lt;/pre&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;b&gt;&lt;span style="font-size:150%;"&gt;Cause&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;SAML Authentication group,&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;In design scenarios, where the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on the group membership sync to put the user into the SAML group, authentication will fail. This is because the user will not be in the Authentication SAML Group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login as new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in, will be able to login and see their group membership synced as they are in the SAML Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Adding Users to the SAML Authentication Group will allow the users to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt; SAML Authentication Group&lt;/a&gt; should be a standalone group that does not depend on the group membership sync. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The SAML Authentication Group should have a Different &lt;a href="https://docs.appian.com/suite/help/24.2/Group_Types.html"&gt;Group Type&lt;/a&gt; then the one used for membership sync.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you are impacted by this behaviour, and wish to record your desire for this feature to be enhanced in further released of Appiah, please work with Appian Support, or your Account Executive, to share your product use case through Product Enhancement Request: &lt;em&gt;#7032 - Group membership sync for multiple IdP providers.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you have further questions, please reach out to Appian Support through a Support Case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-311] SAML Group Membership Sync Users unable to sign in</title><link>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in/revision/2</link><pubDate>Mon, 29 Jul 2024 06:09:03 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6f4d4cd1-4d0c-4fe0-aed4-1edebd3a93d9</guid><dc:creator>Appian Community</dc:creator><comments>https://community.appian.com/support/w/kb/3566/kb-2323-saml-group-membership-sync-users-unable-to-sign-in#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Appian Community on 7/29/2024 6:09:03 AM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;Users are unable to authenticate through SAML when adding users to the SAML Authentication group through&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt; SAML Group Membership Sync&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Symptom&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;SAML works for new users configured with &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create New User on Sign In&lt;/a&gt;&amp;rdquo;, and users already in the SAML Authentication group, but for users being added to the SAML group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#group-membership-synchronization"&gt;&amp;ldquo;Group Membership Sync&amp;rdquo;&lt;/a&gt; feature, SAML authentication fails and the user is not signed in.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;User is not signed in as confirmed in logging:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Tomcat-access.log:&amp;nbsp;&lt;br /&gt;&lt;/span&gt;&lt;pre class="ui-code" data-mode="text"&gt;/suite/saml/AssertionConsumer - 401 0.068&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;Tomcat-stdOut.log:&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;INFO&amp;#160; com.appiancorp.security.auth.saml.SamlFilter - Authentication Error: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken
org.springframework.security.authentication.BadCredentialsException: Invalid Saml settings for com.appiancorp.security.auth.saml.SamlAuthToken&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;Login-audit.log&lt;br /&gt;&lt;pre class="ui-code" data-mode="text"&gt;&amp;lt;USERNAME&amp;gt;,Failed …&lt;/pre&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;b&gt;&lt;span style="font-size:150%;"&gt;Cause&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;When performing SAML Authentication, Appian checks whether the unauthenticated user is in the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt;SAML Authentication group,&lt;/a&gt;&amp;nbsp;and uses this to decide authentication success/failure. After authentication, if the user is in an authenticated group, Appian performs the group membership sync.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;span style="font-weight:400;"&gt;In design scenarios, where the &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Authentication Group depends on the group membership sync to put the user into the SAML group, authentication will fail. This is because the user will not be in the Authentication SAML Group before authentication, and will not be authenticated.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;New users are able to login as new users are added to the SAML Authentication group through the &lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#create-new-users-upon-sign-in"&gt;&amp;ldquo;Create Users Upon Sign In&lt;/a&gt;&amp;rdquo; feature.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Additionally, users in the Authentication Group prior to sign in, will be able to login and see their group membership synced as they are in the SAML Authentication Group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;Adding Users to the SAML Authentication Group will allow the users to sign in. This can be done manually, through a nested group, or group rule.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The&lt;a href="https://docs.appian.com/suite/help/24.2/SAML_for_Single_Sign-On.html#authentication-group"&gt; SAML Authentication Group&lt;/a&gt; should be a standalone group that does not depend on the group membership sync. &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style="font-size:inherit;"&gt;The SAML Authentication Group should have a Different &lt;a href="https://docs.appian.com/suite/help/24.2/Group_Types.html"&gt;Group Type&lt;/a&gt; then the one used for membership sync.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you are impacted by this behaviour, and wish to record your desire for this feature to be enhanced in further released of Appiah, please work with Appian Support, or your Account Executive, to share your product use case through Product Enhancement Request: &lt;em&gt;&lt;strong&gt;#7032 - Group membership sync for multiple IdP providers.&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;font-weight:400;"&gt;If you have further questions, please reach out to Appian Support through a Support Case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>