Troubleshooting: Single Sign-On
This topic provides strategies for diagnosing and resolving Single Sign-On problems.
Certificate expired.
Users receive this error when attempting Single Sign-On:
- The SAML login is failing
- Unable to process SAML response.
This error displays because the certificate is expired or the values don't match the certificate that you use for the SAML response. Use a certificate decoder to verify the SSO certificate expiration date.
Reupload the certificate from your identity provider into Workday Peakon Employee Voice.
- Copy the certificate generated by the identity provider.
- In Peakon, click .
- Paste the certificate into theCertificatefield.
- ClickSave.
Security:
Administrator
access in Peakon and Single Sign-On identity provider.Employee not assigned to Workday Peakon application.
Users receive this error when attempting Single Sign-On:
- The signed in user (email address) is not assigned to a role for the application (identifying number) (Peakon)
- AADSTS50105: Your administrator has configured the application Peakon to block users unless they are specifically granted ('assigned') access to the application.
The signed-in user is blocked as they're not a direct member of a group with access, their email address set in the SSO provider differs from their email address in Peakon, or haven't had access directly assigned by an administrator. The user must belong to a group that is assigned to the Peakon application, or be assigned directly
Ensure that both the name and email address of the user in the SSO provider matches the information provided on their employee record in Peakon.
- In the SSO provider, check the access of the user or user group.
- Edit access or the email address, if applicable.
- In Peakon, go to .
- Search for the employee record and compare the information.
- Editthe employee record, if applicable.
Security:
Administrator
access in Peakon and Single Sign-On identity provider.