Product Version: 6.5.0.0
Overview
Single Sign-On (SSO) is an authentication solution that allows users to log in to multiple applications and websites with a single set of credentials. Modern users often access applications directly from browsers, making access management critical. SSO improves security and user experience by allowing users to access all password-protected resources without repeated logins once their identity is validated. This KBA addresses the 'Email attribute not set' error that may appear on the Saner CVEM SSO access portal, even after configuring SSO in the vendor’s admin console.
Applicable Platforms
On-Cloud
On-Premise / In-House
Pre-requisites for Azure AD SSO
To configure Azure AD SSO for Saner CVEM, ensure the following information is available:
Identity Provider Single Sign-On URL
X.509 Certificate
Issuer ID
Cause of the 'Email Attribute Not Set' Error
This error occurs when the SSO configuration does not include the required Email attribute in the user claims. Without this attribute, Saner CVEM cannot map the user’s email during authentication, causing login failures.
Steps to Fix the Issue
The following steps demonstrate how to include the required email attribute in Azure AD SSO configuration:
Step 1: Log in to Azure Admin Center
Open a web browser and log in to the Microsoft Azure Admin Center.
Navigate to Enterprise Applications → All Applications → Saner CVEM SSO Setup.
Step 2: Navigate to User Attributes & Claims
Go to Manage → Single Sign-On → User Attributes & Claims.
Click Edit to modify existing claims.
Step 3: Add Email Attribute Claim
Click Add New Claim.
Set the Claim Name as
Email
.Set the Attribute as
user.email
.Click Save.
Step 4: Re-enforce SSO Authentication
Re-enforce the existing SSO authentication setup in Saner CVEM for the affected user.
Step 5: Retry SSO Access
Ask the end-user to retry logging in through their browser.
The 'Email attribute not set' error should now be resolved.
References
For more detailed guidance on SSO configuration, refer to the Saner CVEM Single Sign-On User Guides:Saner CVEM Platform Function Guides
Conclusion
The 'Email attribute not set' error is a common SSO misconfiguration issue. By adding the required Email attribute claim in Azure AD and re-enforcing the SSO authentication, users can successfully log in to Saner CVEM without encountering errors. Following these steps ensures smooth SSO access while maintaining secure authentication practices.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article