Troubleshoot and Validate Microsoft Entra ID Configuration
Use the information in this topic to validate and troubleshoot SAML SSO between Microsoft Entra ID and Routing Director.
This topic provides a structured approach for validating and troubleshooting SAML Single Sign-On (SSO) between Microsoft Entra ID and Routing Director. Use these procedures during deployment, testing, and operational support.
Perform Initial SSO Validation
Use the following checks to quickly identify the most common causes of authentication failures. When SSO authentication fails, verify the following in order:
User Assignment
- Confirm the user or group is assigned to the Routing Director enterprise application in Microsoft Entra ID.
- Check Entra sign-in logs for User not assigned to application errors.
Login Method
- Verify users launch Routing Director from the Entra My Apps portal or the IdP-initiated SSO URL.
- Routing Director does not support SP-initiated SSO from the local login page.
Certificate Validation
- Verify the Entra Base64 signing certificate matches the certificate uploaded to Routing Director.
- Confirm certificate thumbprints are identical.
SAML Assertion Validation
- Verify the following values in the SAML response:
- Audience matches the Routing Director Entity ID.
- Recipient/ACS matches the Routing Director ACS URL.
- NameID is present and maps to a valid Routing Director user.
- Role attribute is present and matches a configured role mapping.
- Verify the following values in the SAML response:
Troubleshoot Common SAML Issues
If initial validation does not identify the issue, inspect the SAML response to verify the assertion contents and configuration values.
Verify the following using browser developer tools or a SAML tracing utility:
- The SAML assertion contains a valid signature.
- The signing certificate matches the certificate configured in Routing Director.
- Audience and Recipient values match the Routing Director configuration.
- NameID and required role attributes are present.
Common causes include:
- Invalid or expired signing certificate
- Entity ID (Audience) mismatch
- ACS URL mismatch
- Missing or incorrect NameID
- Missing role attribute
- User launching from the Routing Director login page instead of Entra ID
Collect Diagnostic Information
When additional troubleshooting is required, collect logs and diagnostic information from both the identity provider and service provider.
Microsoft Entra ID
Review:
- Enterprise Application sign-in logs
- Conditional Access results
- MFA requirements
- User assignments
You can also use the Test Single Sign-On feature to generate a test SAML response for validation.
Routing Director
Collect authentication and identity service logs and correlate timestamps with Entra sign-in events.
For additional troubleshooting, use the SSO failures API:
https://<ui-address>/api/v1/orgs/<org-id>/ssos/<ssos-id>/failures
Security and Compliance Validation
Use the following tasks to verify that the SSO deployment aligns with your organization's security and operational requirements, and to ensure that certificate and session management practices are in place to support long-term service availability.
Validate Certificate Management
To prevent authentication failures caused by certificate expiration, verify that certificate life-cycle management processes are in place.
- Monitor expiration of the Entra token-signing certificate.
- Schedule certificate rotation before expiration.
- Update the certificate in Routing Director during rotation activities.
Validate Session Management
Review session and logout behavior to ensure it aligns with organizational security requirements.
- Verify session timeout settings align with organizational policy.
- Review Entra authentication policies and Routing Director session behavior.
- If Single Logout (SLO) is configured, validate logout functionality and user experience.
Post-Deployment Validation
Use the following tasks after deployment to verify that the SSO configuration is operating as expected and that the necessary operational controls and evidence have been captured.
Collect Configuration Evidence
Capture configuration evidence to support operational handoff, audits, and future troubleshooting.
Microsoft Entra ID
Capture screenshots of:
- SAML Basic Configuration
- Entity ID
- Reply URL (ACS)
- SAML Certificates
- User and Group Assignments
Routing Director
Capture screenshots of:
- Identity Provider configuration
- Role mappings
- Successful user login and assigned role
Perform Operational Validation
After deployment, validate that the SSO configuration continues to operate as expected in production.
Within one week of deployment:
- Review Entra sign-in logs for recurring failures.
- Verify user and group assignments remain accurate.
- Confirm certificate rotation ownership and reminders are documented.
- Test break-glass administrative access to ensure administrators can access Routing Director during an IdP outage.