O365 WS-Fed authentication fails with RSA SecurID Access
Originally Published: 2020-02-05
Article Number
Applies To
RSA Product/Service Type: Cloud
Issue
Sorry but we're having trouble signing you in.
ADSTS20012: An error occurred when we tried to process a WS-Federation message. The message was invalid.
ADSTS20012: An error occurred when we tried to process a WS-Federation message. The message was invalid.
The authentication on the activity monitor shows that the user was successfully authenticated. Following the successful authentication, there is an entry for the user logout. There is then another authentication request sent, which receives a response that the user is already authenticated.
Cause
This error message also appears if you have configured multiple IDRs with the same portal hostname. This causes the load balancer to open a session with the wrong IDR during the authentication process.
Resolution
- Create static DNS entries to map the load balancer hostname to each IDR's proxy IP address. For more information, see 000037406 - RSA SecurID Access O365 WS-Fed Authentication Fails Intermittently.
- Ensure that each IDR has its unique portal hostname and correct DNS entries mapping to the proxy interface.
- Confirm that the load balancer hostname is different from the IDR hostname.
Related Articles
RSA SecurID Access O365 WS-Fed Authentication Fails Intermittently 113Number of Views Workday Web Service Identity Collector (IDC) on WebSphere fails with 'Failed to add WS-Security header to request' error i… 87Number of Views Tape Silo w/Encryption showing key error 7Number of Views Microsoft SharePoint - SSO Agent - WS-Fed Configuration - RSA Ready SecurID Access Implementation Guide 34Number of Views Microsoft SharePoint 2016 - WS-Fed SSO Agent Configuration - RSA Ready Implementation Guide 24Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?