<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure SSO login fails after MFA in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4762059#M250783</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;While that article didn't DIRECTLY provide the solution (most of it relates to a Duo DAG, which we don't use), it did enough to lead me to the&amp;nbsp;&lt;STRONG&gt;SAML login history&lt;/STRONG&gt; page which showed this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Meraki SAML error.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/174342i8B8A258C2C77DFB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Meraki SAML error.png" alt="Meraki SAML error.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Which itself was enough to point me back to the 'App roles' blade in Azure to change the value "meraki.write" to "meraki_write", which, as you can see, is now working.&lt;/P&gt;&lt;P&gt;Cheers, Marce!&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 13:14:38 GMT</pubDate>
    <dc:creator>jjeffery</dc:creator>
    <dc:date>2023-01-25T13:14:38Z</dc:date>
    <item>
      <title>Azure SSO login fails after MFA</title>
      <link>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4761936#M250779</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I've followed these two articles to set up SSO logins:&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Managing_Dashboard_Access/Configuring_SAML_SSO_with_Azure_AD" target="_blank" rel="noopener"&gt;https://documentation.meraki.com/General_Administration/Managing_Dashboard_Access/Configuring_SAML_SSO_with_Azure_AD&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/meraki-dashboard-tutorial" target="_blank" rel="noopener"&gt;Tutorial: Azure Active Directory single sign-on (SSO) integration with Meraki Dashboard - Microsoft Entra | Microsoft Learn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After which, launching the new URL seems to work in that it asks for my account name, then my password, then asks for my Duo MFA preference (I choose 'Push'), then reacts as expected after I confirm the Duo prompt on my phone...then it errors out with this message:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Meraki SSO fail.png" style="width: 582px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/174314iE3A79D3395CD87F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Meraki SSO fail.png" alt="Meraki SSO fail.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Azure Sign-in logs show "Success". The Meraki Dashboard login attempts only logs our primary 'local' account logins. I don't know where else to look!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 10:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4761936#M250779</guid>
      <dc:creator>jjeffery</dc:creator>
      <dc:date>2023-01-25T10:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: Azure SSO login fails after MFA</title>
      <link>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4762032#M250782</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://help.duo.com/s/article/5594?language=en_US" target="_blank"&gt;https://help.duo.com/s/article/5594?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 12:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4762032#M250782</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-01-25T12:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Azure SSO login fails after MFA</title>
      <link>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4762059#M250783</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;While that article didn't DIRECTLY provide the solution (most of it relates to a Duo DAG, which we don't use), it did enough to lead me to the&amp;nbsp;&lt;STRONG&gt;SAML login history&lt;/STRONG&gt; page which showed this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Meraki SAML error.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/174342i8B8A258C2C77DFB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Meraki SAML error.png" alt="Meraki SAML error.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Which itself was enough to point me back to the 'App roles' blade in Azure to change the value "meraki.write" to "meraki_write", which, as you can see, is now working.&lt;/P&gt;&lt;P&gt;Cheers, Marce!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 13:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/azure-sso-login-fails-after-mfa/m-p/4762059#M250783</guid>
      <dc:creator>jjeffery</dc:creator>
      <dc:date>2023-01-25T13:14:38Z</dc:date>
    </item>
  </channel>
</rss>

