Hi @Jon Elkin
Thank you for posting this in Microsoft Q&A.
Thank you for providing a detailed explanation of the issue you're facing. I understand that you're encountering an error message (AADSTS7500525) when a user who is not authorized to access Zendesk attempts to log in using Microsoft Entra SAML-based Single Sign-On (SSO). The current behavior can be misleading and make troubleshooting difficult.
You receive error AADSTS75005
when trying to sign into an application that has been set up to use Microsoft Entra ID for identity management using SAML-based SSO.
Microsoft Entra ID doesn't support the SAML request sent by the application for single sign-on. Some common issues are:
- Missing required fields in the SAML request.
- SAML request encoded method.
Based on the request you provided it seems you have included required fields in SAML request. I would request you to please cross check your SAML request
https://learn.microsoft.com/en-us/entra/identity-platform/single-sign-on-saml-protocol#authnrequest
If the issue still persistent Capture the SAML request. Follow the tutorial How to debug SAML-based single sign-on to applications in Microsoft Entra ID to learn how to capture the SAML request and contact the application vendor.
Hope this helps. Do let us know if you any further queries.
Thanks,
Navya.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.