The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'urn:oasis:names:tc:SAML:1.0:am:password

Benollins-5339 0 Reputation points
2025-01-21T10:24:20.31+00:00

We have a Relying Party setup for SSO for a client to our application, however they are unable to log in using SSO. Upon investigation, i have found the below messages within ADFS event logs:

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'urn:oasis:names:tc:SAML:1.0:am:password' for the relying party 'https://SITEAPPURL.com'. Authentication type: Desired authentication type(s): urn:oasis:names:tc:SAML:1.0:am:password Relying party: https://SITEAPPURL.com This request failed.

And another error:

An error occurred during processing of a token request. The data in this event may have the identity of the caller (application) that made this request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error. Additional Data

Caller: UPN OF SSO USER

OnBehalfOf user:

ActAs user:

Target Relying Party: https://SITEURL.com

Device identity:

User action: Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

We have other clients setup in the same way with no issues and so i cannot believe that any global ADFS settings require being changed. Many thanks for your help.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,291 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.