TICKET HX-1042

SSO redirect loop after IdP migration

Status: Resolved Category: Authentication Priority: P1 Customer: Maria Chen (Northwind Logistics) Agent: Devon Park
Maria Chen Customer 2024-03-12 09:14 UTC

We migrated from Okta to Azure AD over the weekend and now nobody on our team can sign in to Helix. We get redirected to Azure, complete the login, and then bounce back to a 'Sign in with SSO' button that just loops. We're locked out workspace-wide. Can you take a look urgently?

Devon Park Helix Support 2024-03-12 09:31 UTC

Hi Maria — sorry for the disruption. A redirect loop after an IdP swap is almost always one of two things: either the new IdP isn't sending the user's email in the SAML NameID field, or the SAML metadata in Helix is still pointing at your old Okta endpoints.

Two quick checks:

  1. In Settings → Security → SSO, has the metadata been replaced with the Azure AD metadata? It should reference login.microsoftonline.com, not okta.com.
  2. In your Azure AD enterprise app, what NameID format is configured? It needs to be emailAddress, not persistent.
Maria Chen Customer 2024-03-12 09:48 UTC

Checked both. Metadata is updated to Azure. NameID format was set to persistent — switching it to emailAddress now. Will re-test.

Maria Chen Customer 2024-03-12 09:55 UTC

That fixed it. Login working now. Out of curiosity, why does NameID format matter so much?

Devon Park Helix Support 2024-03-12 10:08 UTC

Glad it's working. Helix uses the SAML NameID to look up or provision the user account. With persistent, your IdP sends an opaque ID that doesn't match any email on file, so Helix can't find your user — and the just-in-time provisioning logic creates a fresh user, but at the next login it tries to look up the same opaque ID, doesn't find a match (because emails were used originally), and bounces you back. The loop is the symptom of that mismatch.

For future migrations: always use emailAddress NameID, and test with one user before flipping the org-wide switch. We document this in the SSO guide. Is there anything else I can help with?

Maria Chen Customer 2024-03-12 10:14 UTC

That's super helpful context, thanks. All set.

RESOLUTION

Customer's Azure AD enterprise app was configured with NameID format `persistent` instead of `emailAddress`, causing Helix's user lookup to fail and trigger a redirect loop. Switching the NameID format to emailAddress in Azure resolved it. Confirmed working with full team.