Troubleshooting Guide for Identity

Jon Gilbert Updated by Jon Gilbert

Overview

This guide is designed to help you troubleshoot login errors when using the OneAdvanced Identity provider for single sign-on (SSO). It covers common issues that may arise during the login process and provides step-by-step guidance on resolving them.

Understanding the ASSO Login Process

The ASSO login process involves the following steps:

  1. You click the login button and are redirected to the identity provider (e.g., Microsoft Azure, Okta).
  2. You authenticate with the identity provider, which returns a token.
  3. The system validates the token and extracts your user data.
  4. The system checks your user details against the Time & Attendance database to verify your licenses and permissions.
  5. If everything is in order, you are logged into Time & Attendance.

Common Login Issues

Login issues can be broadly categorized into two types:

  • 403 Forbidden Errors: These are system-level issues related to configuration, licensing, or token validation.
  • 401 Unauthorised Errors: These are user-level issues related to account or credential problems.

Troubleshooting Login Errors

Employee Login Errors

403 Forbidden Errors (System Issues)
  1. Identity Provider Communication Problems:
  • Check the identity provider configuration and connectivity.
  • Symptoms: "Access Denied" or blank page.
  • Common causes: Identity provider outage, network issues, or incorrect redirect URLs.
  1. Token Exchange Failures:
  • Verify the token endpoint configuration.
  • Symptoms: "Access Denied".
  • Common causes: Expired or invalid authorization code, mismatched client credentials, or server clock mismatch.
  1. License Validation Failures:
  • Check license assignments.
  • Symptoms: "Access Denied".
  • Common causes: License expired, missing Web/Time & Attendance license, or company license limit reached.
  1. General Authentication System Failure:
  • Check system logs.
  • Symptoms: "Access Denied".
  • Common causes: DB connection issues, authentication service down, or corrupted session data.
401 Unauthorised Errors (User Issues)
  1. Invalid User Credentials or Account Issues:
  • Check the Time & Attendance user account.
  • Symptoms: Specific error message.
  • Common causes: User disabled/locked, wrong group/role assignments, or terminated employment.

Token Validation Flow Details

The token validation process involves several steps:

  1. Token Format Validation: Check for corrupted tokens, wrong format, or encoding mistakes.
  2. Token Signature Verification: Verify the token signature.
Common issues:

Certificate rotations, clock drift, or wrong signing key.

  1. Claims Extraction: Check for missing claims, incorrect formats, or config changes.
  2. User Lookup in Time & Attendance: Verify user creation, mapping, and ID.
  3. License/Permission Validation: Check for expired licenses, missing features, or license limits reached.

Supervisor Login Behaviour

Supervisors using ASSO are redirected to the employee login flow. Errors appear identical to employee login errors.

Troubleshooting Guide

To quickly diagnose issues, ask yourself:

  1. Does the issue affect all users? (Yes: System issue; No: User issue)
  2. Can the user access other systems via the same SSO? (Yes: Time & Attendance issue; No: Identity provider issue)
  3. When did the issue start? (After update: Config fix needed; Suddenly: User-level issue; New user: Provisioning issue)

Common Resolution Steps

For 403 Forbidden errors:
  1. Check identity provider status.
  2. Verify Time & Attendance configuration.
  3. Test with a known working account.
  4. Check logs.
  5. Verify license assignments.
For 401 Unauthorised errors:
  1. Check user account status.
  2. Validate identity provider group memberships.
  3. Check license assignments.
  4. Verify employment status.
  5. Test alternate login path.

By following this guide, you should be able to identify and resolve common login issues related to the OneAdvanced Identity provider. If you're still experiencing problems, please contact the support team for further assistance.

Was this article useful?

Contact