000038149 - AADSTS50107: Requested federation realm object 'http:/<Identity Router FQDN>/' does not exist when trying to access the Microsoft Azure portal for RSA SecurID Access

Document created by RSA Customer Support Employee on Jan 3, 2020
Version 1Show Document
  • View in full screen mode

Article Content

Article Number000038149
Applies ToRSA Product Set: SecurID Access
RSA Product/Service Type: Cloud
Product Name: Microsoft Office 365
Product Description: WS-federation integration with SecurID Access
IssueWhen trying to access the Microsoft Azure portal, the user tries to login and the portal returns the following error:
 AADSTS50107: Requested federation realm object 'http://<Identity Router FQDN>/' does not exist.

On the cloud admin user event monitor, the user is authenticated successfully using the password but still not being able to login to Microsoft Azure.
CauseThis issue is usually caused by mismatched configuration from either the Microsoft Azure side or on the application side for the cloud admin.
  1. Check the WS-federation configuration on the Azure side through Windows PowerShell by running the command below:

Get-MsolDomainFederationSettings –DomainName $domain | Format-List *

Output of the configurations on the MS Azure side

  1. Compare all the output of the configuration with the configuration of the application on the cloud admin side.

Cloud admin configurations

The difference could be a very minor between the URI on both sides and can be as simple as an extra backslash at the end of the URI.  For example, in the strings below, the first IssuerUri is on the Microsoft side:

IssuerUri                              : http://<Identity Router FQDN>.com

Note the difference with the IssuerUri on the cloud admin side: 

IssuerUri                              : http://<Identity Router FQDN>.com/

  1. Change the URI on either side so that they match each other.
  2. Make sure all other URIs also match on both sides 

For more information, see the Microsoft Office 365 - WS-Federation SSO Agent Configuration - RSA Ready SecurID Access Implementation Guide.