Troubleshoot and Validate Microsoft Entra ID Configuration

Use the information in this topic to validate and troubleshoot SAML SSO between Microsoft Entra ID and Routing Director.

This topic provides a structured approach for validating and troubleshooting SAML Single Sign-On (SSO) between Microsoft Entra ID and Routing Director. Use these procedures during deployment, testing, and operational support.

Perform Initial SSO Validation

Use the following checks to quickly identify the most common causes of authentication failures. When SSO authentication fails, verify the following in order:

  1. User Assignment

    • Confirm the user or group is assigned to the Routing Director enterprise application in Microsoft Entra ID.
    • Check Entra sign-in logs for User not assigned to application errors.
  2. Login Method

    • Verify users launch Routing Director from the Entra My Apps portal or the IdP-initiated SSO URL.
    • Routing Director does not support SP-initiated SSO from the local login page.
  3. Certificate Validation

    • Verify the Entra Base64 signing certificate matches the certificate uploaded to Routing Director.
    • Confirm certificate thumbprints are identical.
  4. SAML Assertion Validation

    • Verify the following values in the SAML response:
      • Audience matches the Routing Director Entity ID.
      • Recipient/ACS matches the Routing Director ACS URL.
      • NameID is present and maps to a valid Routing Director user.
      • Role attribute is present and matches a configured role mapping.

Troubleshoot Common SAML Issues

If initial validation does not identify the issue, inspect the SAML response to verify the assertion contents and configuration values.

Verify the following using browser developer tools or a SAML tracing utility:

  • The SAML assertion contains a valid signature.
  • The signing certificate matches the certificate configured in Routing Director.
  • Audience and Recipient values match the Routing Director configuration.
  • NameID and required role attributes are present.

Common causes include:

  • Invalid or expired signing certificate
  • Entity ID (Audience) mismatch
  • ACS URL mismatch
  • Missing or incorrect NameID
  • Missing role attribute
  • User launching from the Routing Director login page instead of Entra ID

Collect Diagnostic Information

When additional troubleshooting is required, collect logs and diagnostic information from both the identity provider and service provider.

Microsoft Entra ID

Review:

  • Enterprise Application sign-in logs
  • Conditional Access results
  • MFA requirements
  • User assignments

You can also use the Test Single Sign-On feature to generate a test SAML response for validation.

Routing Director

Collect authentication and identity service logs and correlate timestamps with Entra sign-in events.

For additional troubleshooting, use the SSO failures API:

Security and Compliance Validation

Use the following tasks to verify that the SSO deployment aligns with your organization's security and operational requirements, and to ensure that certificate and session management practices are in place to support long-term service availability.

Validate Certificate Management

To prevent authentication failures caused by certificate expiration, verify that certificate life-cycle management processes are in place.

  • Monitor expiration of the Entra token-signing certificate.
  • Schedule certificate rotation before expiration.
  • Update the certificate in Routing Director during rotation activities.

Validate Session Management

Review session and logout behavior to ensure it aligns with organizational security requirements.

  • Verify session timeout settings align with organizational policy.
  • Review Entra authentication policies and Routing Director session behavior.
  • If Single Logout (SLO) is configured, validate logout functionality and user experience.

Post-Deployment Validation

Use the following tasks after deployment to verify that the SSO configuration is operating as expected and that the necessary operational controls and evidence have been captured.

Collect Configuration Evidence

Capture configuration evidence to support operational handoff, audits, and future troubleshooting.

Microsoft Entra ID

Capture screenshots of:

  • SAML Basic Configuration
    • Entity ID
    • Reply URL (ACS)
  • SAML Certificates
  • User and Group Assignments

Routing Director

Capture screenshots of:

  • Identity Provider configuration
  • Role mappings
  • Successful user login and assigned role

Perform Operational Validation

After deployment, validate that the SSO configuration continues to operate as expected in production.

Within one week of deployment:

  • Review Entra sign-in logs for recurring failures.
  • Verify user and group assignments remain accurate.
  • Confirm certificate rotation ownership and reminders are documented.
  • Test break-glass administrative access to ensure administrators can access Routing Director during an IdP outage.