Issue
- The following error occurs while configuring Liferay as SP and ADFS as Idp.
-
At Liferay end: ERROR [ajp-nio-0.0.0.0-8009-exec-10][BaseSamlStrutsAction:59] urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy
-
At ADFS end: Microsoft.IdentityServer.Protocols.Saml.InvalidNameIdPolicyException: MSIS7070: The SAML request contained a NameIDPolicy that was not satisfied by the issued token. Requested NameIDPolicy: AllowCreate: True Format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress SPNameQualifier: Actual NameID properties: null
-
Environment
- Liferay DXP 7.2
Resolution
-
When there are missing claim rules (CR and TR) at ADFS, or when claim rules are configured incorrectly, these types of errors arise.
- The Name ID attribute has not been set at the TR rule, in this case, it should be as follows