Resolving 'Email Attribute Not Set' Error on Saner CVEM SSO Access Portal

Modified on Fri, 26 Sep at 5:18 PM

Product Version: 6.5.0.0


Overview

Single Sign-On (SSO) is an authentication solution that allows users to log in to multiple applications and websites with a single set of credentials. Modern users often access applications directly from browsers, making access management critical. SSO improves security and user experience by allowing users to access all password-protected resources without repeated logins once their identity is validated. This KBA addresses the 'Email attribute not set' error that may appear on the Saner CVEM SSO access portal, even after configuring SSO in the vendor’s admin console.


Applicable Platforms

  • On-Cloud

  • On-Premise / In-House


Pre-requisites for Azure AD SSO

To configure Azure AD SSO for Saner CVEM, ensure the following information is available:

  • Identity Provider Single Sign-On URL

  • X.509 Certificate

  • Issuer ID


Cause of the 'Email Attribute Not Set' Error

This error occurs when the SSO configuration does not include the required Email attribute in the user claims. Without this attribute, Saner CVEM cannot map the user’s email during authentication, causing login failures.


Steps to Fix the Issue

The following steps demonstrate how to include the required email attribute in Azure AD SSO configuration:


Step 1: Log in to Azure Admin Center

  1. Open a web browser and log in to the Microsoft Azure Admin Center.

  2. Navigate to Enterprise Applications → All Applications → Saner CVEM SSO Setup.


Step 2: Navigate to User Attributes & Claims

  1. Go to Manage → Single Sign-On → User Attributes & Claims.

  2. Click Edit to modify existing claims.


Step 3: Add Email Attribute Claim

  1. Click Add New Claim.

  2. Set the Claim Name as Email.

  3. Set the Attribute as user.email.

  4. Click Save.


Step 4: Re-enforce SSO Authentication

  1. Re-enforce the existing SSO authentication setup in Saner CVEM for the affected user.


Step 5: Retry SSO Access

  1. Ask the end-user to retry logging in through their browser.

  2. The 'Email attribute not set' error should now be resolved.


References

For more detailed guidance on SSO configuration, refer to the Saner CVEM Single Sign-On User Guides:Saner CVEM Platform Function Guides


Conclusion

The 'Email attribute not set' error is a common SSO misconfiguration issue. By adding the required Email attribute claim in Azure AD and re-enforcing the SSO authentication, users can successfully log in to Saner CVEM without encountering errors. Following these steps ensures smooth SSO access while maintaining secure authentication practices.

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article