cisco onprem uc · stub
Troubleshooting SAML SSO sign-in failures in Unified CM
Verified 2026-10-02 · 58 sources · tier 2
Also known as CUCM SAML SSO troubleshooting, Unified CM SSO login failure.
Stub. This topic has 58 sources and no published article. The sources below are everything recorded so far.
So far, no summary has been generated for this topic. The sources below are everything recorded so far.
See also
Related to
- Identity SSO and directory provisioning for UC — General identity and SSO concepts; this topic is the Unified CM specific troubleshooting slice
- Setting up SAML SSO for Unified CM — Setup counterpart; this topic covers failure symptoms and recovery after SSO has been enabled
- Setting up multi-server SAN certificates in Unified CM and IM and Presencestub — Cluster-wide SSO with the Tomcat certificate depends on a multi-server Tomcat certificate
- Troubleshooting Jabber and Webex App sign-in on Unified CM on premisesstub — Jabber SSO sign-in failures share the IdP trust and uid mapping causes but are scoped to that topic
- Unified CM certificate renewal — Tomcat certificate regeneration forces new SP metadata to be uploaded to the IdP
Sources
- 1From Unified CM 11.5 the AuthnRequest carries AssertionConsumerServiceIndex instead of an ACS URL, so the IdP must resolve the index from imported SP metadata; Cisco states there is no workaround (CSCvc56596).Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · AuthnRequest Format; Common Issues - AssertionConsumerServiceIndex Support · Checked 2026-10-02
- 2By default AD FS generates new token-signing and token-decryption certificates automatically (AutoCertificateRollover), and each federation partner must then be updated with the new certificate to avoid an outage.Obtain and configure token signing and token decryption certificates for AD FS · Determine whether AD FS renews the certificates automatically · Checked 2026-10-02
- 3With AD FS, the Unified CM error 'Invalid Status code in Response' is resolved by checking claim-rule syntax, entityID capitalisation against the metadata files, and the AD FS event logs.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Common Issues - Invalid Status Code (AD FS) · Checked 2026-10-02
- 4Federation partners that cannot consume AD FS federation metadata must be sent the new certificate's public key manually and change their own trust configuration.Obtain and configure token signing and token decryption certificates for AD FS · Update federation partners - Partners who can't consume federation metadata · Checked 2026-10-02
- 5Microsoft says all federation partners must consume new AD FS signing certificates before the current one's Not After date and to plan this at least 60 days in advance.Obtain and configure token signing and token decryption certificates for AD FS · Determine when the current certificates expire · Checked 2026-10-02
- 6AD FS CertificateGenerationThreshold sets how many days before Not After a new certificate is generated, and CertificatePromotionThreshold sets how many days after generation it becomes primary.Obtain and configure token signing and token decryption certificates for AD FS · Determine whether AD FS renews the certificates automatically (threshold bullets) · Checked 2026-10-02
- 7AD FS token-signing and token-decrypting certificates are usually self-signed and valid for one year.Certificate renewal for Microsoft 365 and Microsoft Entra users · Default configuration of AD FS for token signing certificates · Checked 2026-10-02
- 8When AD FS rolls its token-signing certificate it publishes metadata with two signing certificates, and Unified CM then fails with 'The signing certificate does not match what's defined in the entity metadata' until metadata holding only the current certificate is imported.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Certificate and Tomcat Impact - Two Certificate Problem (AD FS) · Checked 2026-10-02
- 9From Unified CM 11.5 the SAML AuthnRequest asks for NameIDPolicy Format urn:oasis:names:tc:SAML:2.0:nameid-format:transient.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · SAML Request and Assertion Structure - AuthnRequest Format · Checked 2026-10-02
- 10Cisco advises clearing the browser cache and retrying if the SAML SSO window still cannot be signed into after the metadata update procedure.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Update Server Metadata After a Domain or Hostname Change (note) · Checked 2026-10-02
- 11The maximum allowed time difference between the IdP and the Unified Communications applications for SAML SSO is 3 seconds.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · SAML-Based SSO Prerequisites > NTP Setup · Checked 2026-10-02
- 12Cluster-wide SSO that uses the Tomcat certificate needs a multi-server Tomcat certificate on all nodes because there is only one metadata file; from 12.0 a system-generated self-signed (ITLRecovery) certificate option avoids this.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Cluster-Wide vs Per-Node Configuration; Certificate and Tomcat Impact (CSCvr49382 note) · Checked 2026-10-02
- 13Before Unified CM 11.5 each node generated its own SP metadata file that had to be uploaded to the IdP separately; 11.5 added a single SAML agreement for the whole cluster.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.5(1) - SAML-Based SSO Solution · SAML-Based SSO Solution - cluster-wide SSO enhancement · Checked 2026-10-02
- 14Cisco defect CSCvf96778 records CTI-based SSO failing when the Unified CM server is defined by IP address rather than hostname in CCMAdmin.Troubleshoot SSO in Cisco Unified Communications Manager · Known Defects - CSCvf96778 · Checked 2026-10-02
- 15Cisco TAC uses utils diagnose test on Unified CM to check NTP and DNS health when SSO assertions are rejected or SSO fails to start.Troubleshoot SSO in Cisco Unified Communications Manager · Common Issues - NTP and DNS items (verification) · Checked 2026-10-02
- 16To see the full SAML response during troubleshooting, TAC suggests temporarily disabling assertion encryption on the IdP.Troubleshoot SSO in Cisco Unified Communications Manager · SAML Response Analysis - encrypted responses · Checked 2026-10-02
- 17Cisco TAC calls DNS the primary requirement for Unified CM SSO; the service providers and the IdP must be resolvable by the user's browser.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · SAML-Based SSO Prerequisites > DNS Setup · Checked 2026-10-02
- 18A capitalisation difference between the Unified CM SP entityID/FQDN and the value used in the IdP claim rule breaks SSO, because entityIDs are compared case-sensitively.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · UID Mapping and AttributeStatement (case sensitivity example); Common Issues - Invalid Status Code · Checked 2026-10-02
- 19Cisco's Entra ID guide states Microsoft Entra ID officially supports only cluster-wide agreements and does not recommend per-node agreements for Unified CM SAML SSO.SAML SSO Microsoft Entra ID Identity Provider · Metadata Requirements · Checked 2026-10-02
- 20With Microsoft Entra ID as IdP, if user.onpremisessamaccountname does not equal the User ID chosen in Unified CM, the administrator must map uid to a different Entra ID attribute that does.SAML SSO Microsoft Entra ID Identity Provider · User Attributes & Claims · Checked 2026-10-02
- 21For Entra ID SSO, the X.509 certificate data sent in the SAML assertion must match the certificate in the Entra ID enterprise application.SAML SSO Microsoft Entra ID Identity Provider · Troubleshooting · Checked 2026-10-02
- 22After a domain or hostname change on a Unified CM server, SAML SSO is not functional until updated server metadata is exported to the IdP and IdP metadata is re-imported.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Update Server Metadata After a Domain or Hostname Change · Checked 2026-10-02
- 23A Unified CM cluster federated to AD FS with default settings is likely to see SSO fail around each yearly token-signing rollover unless the AD FS metadata is re-imported, because Cisco documents only manual IdP metadata import.inferredSAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Update IdP Metadata (manual file import), read with ms-learn-adfs-ts-td-certificates and ms-learn-entra-fed-o365-cert-renewal · Checked 2026-10-02
- 24In per-node SSO mode, a certificate or hostname change on one node is likely to break SSO only on that node, since each node has its own metadata and agreement.inferredSAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.5(1) - SAML-Based SSO Solution · SAML-Based SSO Solution - per-node metadata, read with the 15 guide's per-node repeat note · Checked 2026-10-02
- 25A SAML response carrying status InvalidNameIDPolicy indicates a NameID policy or claim-rule definition problem on the IdP, and Cisco TAC directs fixing the claim rule there.Troubleshoot SSO in Cisco Unified Communications Manager · Common Issues - Invalid NameID Policy or Incorrect Claim Rules · Checked 2026-10-02
- 26At least one LDAP-synchronized user must be in the Standard CCM Super Users group so that Cisco Unified CM Administration remains reachable once SSO is on.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · SAML Single Sign-On Prerequisites · Checked 2026-10-02
- 27A Unified CM SSO log line reading Time Valid?:false means the assertion's NotBefore/NotOnOrAfter window failed validation, pointing to NTP misalignment between Unified CM and the IdP.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Assertion Validation Elements - Time Validation; Common Issues - NTP Time Mismatch · Checked 2026-10-02
- 28Unified CM SP metadata regenerates when the SSO certificate is switched between self-signed and Tomcat certificates, or when Tomcat certificates are regenerated to ITL Recovery certificates.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · SAML SSO Deployment Interactions and Restrictions - metadata regeneration · Checked 2026-10-02
- 29Using SAML SSO with Okta to sign in to Cisco Unified RTMT requires at least Java 8.221.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.5(1) - SAML-Based SSO Solution · SAML-Based SSO Solution - RTMT with Okta note · Checked 2026-10-02
- 30On Unified CM 12.x, OS Administration and Disaster Recovery System can return 403 Forbidden after SSO is enabled because those platform applications do not reference the end-user table used by CM Administration.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Common Issues - OS Administration/Disaster Recovery Access · Checked 2026-10-02
- 31A platform user for OS Admin/DRS SSO is created with set account name on the CLI, which prompts for privilege level (0 read-only, 1 read/write), the LDAP uid, and whether the user may sign in through the recovery URL.Configure SSO for OS Admin and DRS in CUCM Version 12.x · Configure - new user (set account name) · Checked 2026-10-02
- 32SSO for OS Admin and DRS (Unified CM 12.0 and later) requires SSO already enabled for CM Administration plus a platform-level user that also exists in the directory the IdP authenticates against.Configure SSO for OS Admin and DRS in CUCM Version 12.x · Requirements; Configure - existing OS Admin user · Checked 2026-10-02
- 33With per-node SAML agreements the SSO configuration procedure is repeated on each Unified CM node, each producing its own metadata file.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Initiate SSO Configuration on Collaboration Applications (per node agreements note) · Checked 2026-10-02
- 34An untrusted-assertion-signer failure after an IdP certificate renewal is fixed by re-exchanging metadata between the IdP and Unified CM.Troubleshoot SSO in Cisco Unified Communications Manager · Common Issues - Untrusted Assertion Signer · Checked 2026-10-02
- 35Only application users with administrative privileges can sign in through the Unified CM recovery URL.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Access the Recovery URL · Checked 2026-10-02
- 36Cisco recommends using the recovery URL before changing a server's domain or hostname, since signing in through it lets the administrator update the server metadata.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Access the Recovery URL · Checked 2026-10-02
- 37The recovery URL is enabled with utils sso recovery-url enable and disabled with utils sso recovery-url disable, and the state should be checked on every cluster node.Troubleshoot SSO in Cisco Unified Communications Manager · CLI Commands (utils sso recovery-url) · Checked 2026-10-02
- 38When SAML SSO is enabled on Unified CM the recovery URL is enabled by default.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Access the Recovery URL · Checked 2026-10-02
- 39The recovery URL bypasses SAML SSO for Cisco Unified CM Administration and Cisco Unified CM IM and Presence Service interfaces, for troubleshooting.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · Access the Recovery URL · Checked 2026-10-02
- 40The Unified CM recovery URL does not work for end users, LDAP or local, signing in to the Self Care portal.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · Access the Recovery URL · Checked 2026-10-02
- 41The Unified CM SSO recovery URL is https://hostname:8443/ssosp/local/login.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Access the Recovery URL · Checked 2026-10-02
- 42The 12.5(1) troubleshooting guide treats a failed redirect to the IdP as an IdP availability, uploaded-metadata or circle-of-trust problem.Troubleshooting Guide for Cisco Unified Communications Manager, Release 12.5(1) - Troubleshooting Features and Services · SAML Single Sign-On troubleshooting - Redirection to IdP fails · Checked 2026-10-02
- 43For SSO failures Cisco TAC collects the Cisco Tomcat, Cisco Tomcat Security and Cisco SSO logs from Unified CM through RTMT.Troubleshoot SSO in Cisco Unified Communications Manager · Log collection via RTMT section · Checked 2026-10-02
- 44Unified CM SAML SSO uses the HTTP Redirect (GET) binding and the HTTP POST binding.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.5(1) - SAML-Based SSO Solution · SAML-Based SSO Solution - bindings · Checked 2026-10-02
- 45When reading a decoded SAML response for Unified CM, TAC checks Version 2.0, InResponseTo matching the request, StatusCode Success, the Issuer, SPNameQualifier equal to the Unified CM FQDN, the NotBefore/NotOnOrAfter window, and the user AttributeValue.Troubleshoot SSO in Cisco Unified Communications Manager · SAML Response Analysis · Checked 2026-10-02
- 46Unified CM SSO logs are not at a detailed level by default; Cisco TAC directs running set samltrace level debug before reproducing an SSO failure.Troubleshoot SSO in Cisco Unified Communications Manager · CLI Commands (set samltrace level) · Checked 2026-10-02
- 47The set samltrace level command is not cluster-wide in Unified CM; it must be run on each node whose SSO behaviour is being traced.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Testing and Validation - CLI Commands note · Checked 2026-10-02
- 48After a server is deleted from a Unified CM cluster that uses cluster-wide SSO, metadata must be re-imported to avoid an index mismatch with the IdP.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · Update Server Metadata After Deleting a Server · Checked 2026-10-02
- 49The SAML login flow supported by Unified CM is SP-initiated.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · SAML Single Sign-On Prerequisites · Checked 2026-10-02
- 50utils sso disable turns off SAML SSO from the CLI and must be run on all cluster nodes, whereas utils sso enable only returns a message because enabling is done from the GUI.Troubleshoot SSO in Cisco Unified Communications Manager · CLI Commands table · Checked 2026-10-02
- 51utils sso status shows the SSO status and configuration parameters of the node it is run on.Troubleshoot SSO in Cisco Unified Communications Manager · CLI Commands table · Checked 2026-10-02
- 52Unified CM SAML service-provider logs are written under tomcat/logs/ssosp/log4j/.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Testing and Validation - Log Path · Checked 2026-10-02
- 53When utils sso status reports SSO enabled but the GUI shows it disabled, Cisco TAC traces the mismatch to the tkssomode field of the processnode table and resynchronises by correcting it and then disabling and re-enabling SSO.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · Common Issues - SSO Status Mismatch (CLI vs GUI) · Checked 2026-10-02
- 54The Run SSO Test step must use an LDAP-synchronized user who has Standard CCM Super User permissions.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · Enable SAML SSO for Cisco Collaboration Applications · Checked 2026-10-02
- 55If the Unified CM Tomcat certificates are regenerated, a new SP metadata file must be generated and uploaded to the IdP.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · SAML SSO Deployment Interactions and Restrictions - Tomcat certificate regeneration · Checked 2026-10-02
- 56The SSO deployment guide's Restart Cisco Tomcat Service task runs utils service restart Cisco Tomcat on all cluster nodes where SSO is enabled.SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration · SAML SSO Additional Tasks > Restart Cisco Tomcat Service · Checked 2026-10-02
- 57The IdP assertion must carry an attribute named uid whose value is a valid Unified CM user; if the attribute statement is missing the login fails.Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM) · UID Mapping and AttributeStatement; Common Issues - Invalid Attribute Statement · Checked 2026-10-02
- 58The mandatory uid attribute must match the attribute used for the LDAP-synchronized user ID in Unified CM.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On · SAML Single Sign-On Prerequisites · Checked 2026-10-02
Documents
tier 2 current vendor documentation
Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage SAML Single Sign-On
tier 2 current vendor documentation
Certificate renewal for Microsoft 365 and Microsoft Entra users
tier 2 current vendor documentation
Configure and Troubleshoot SSO on Cisco Unified Communications Manager (CUCM)
tier 2 current vendor documentation
Configure SSO for OS Admin and DRS in CUCM Version 12.x
tier 2 current vendor documentation
Obtain and configure token signing and token decryption certificates for AD FS
tier 2 current vendor documentation
SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 12.5(1) - SAML-Based SSO Solution
tier 2 current vendor documentation
SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration
tier 2 current vendor documentation
SAML SSO Microsoft Entra ID Identity Provider
tier 2 current vendor documentation
Troubleshoot SSO in Cisco Unified Communications Manager
tier 2 current vendor documentation
Troubleshooting Guide for Cisco Unified Communications Manager, Release 12.5(1) - Troubleshooting Features and Services
Cite this page
APA
WarmTransfer. (2026, October 2). Troubleshooting SAML SSO sign-in failures in Unified CM. WarmTransfer. https://warmtransfer.net/knowledge/cucm-sso-troubleshooting
BibTeX
@misc{warmtransfer-cucm-sso-troubleshooting,
title = {Troubleshooting SAML SSO sign-in failures in Unified CM},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/cucm-sso-troubleshooting},
note = {Verified 2026-10-02}
}