Error message: SAML 2.0 Authentication Failed: User Identifier Not Found

Problem

I am receiving this error when using SAML 2.0: “SAML 2.0 Authentication Failed: User Identifier Not Found.”

Cause

This happens when a UID or NAME ID is not passed from the ADFS Claim rules.

In ADFS the Relying Party Trust needs to have a Claim rule that passes either a UID or a NAME ID value. When you run a Workfront Test Connection, it should show this if successful.

Access requirements

Expand to view access requirements for the functionality in this article.
table 0-row-2 1-row-2 2-row-2 layout-auto html-authored no-header
Adobe Workfront package Any
Adobe Workfront license

Standard

Plan

Access level configurations System Administrator

For information, see Access requirements in Workfront documentation.

Solution

  1. When editing the ADFS INFO, in the Relying Party Trusts > Select object >Edit Claim Rules.

  2. The LDAP Attribute (left column) should have E-Mail Addresses (or any unique identifier).

  3. The Outgoing Claim Type (right column) should be Name ID.

    note note
    NOTE
    It does not have to have the LDAP Attribute E-Mail Addresses. Any unique identifier that will identify the user can be used but it must be passed into Adobe Workfront as the NAME ID.
recommendation-more-help
5f00cc6b-2202-40d6-bcd0-3ee0c2316b43