| Description | This article describes how to fix the admin authentication with SAML SSO if it breaks when upgrading to firmware v7.4.1. |
| Scope | FortiGate v7.4.1. |
| Solution |
This is known as issue 949699.
Error received:
Sorry, but we’re having trouble signing you in.
AADSTS7500525: There was an XML error in the SAML message at line 1, position 504. Verify that the XML content of the SAML messages conforms to the SAML protocol specifications.
Request Id: d5b05590-c9e5-4697-8ed0-499e0bec0800
Workaround: In order to fix the issue, manually configure the entity ID as it was configured before the upgrade:
From the CLI:
config system saml set entity-id <SP entity ID> end
From the GUI:
Related articles: Technical Tip: How to fix crashing SAML daemon Technical Tip: A basic explanation of SAML authentication Technical Tip: Configuring SAML SSO login for FortiGate Admin Web GUI Access with JumpCloud acting a... Technical Tip: Set up SAML admin LDAP login on FortiGate (SP) with FortiAuthenticator (IDP) Technical Tip: Configuring FortiGate SSO Administrators with ADFS as SAML IdP Technical Tip: Configure SAML SSO for WiFi SSID over Captive Portal with Azure AD as IdP |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.