SAML Assertion Not Passed from Azure to Marketo

A document by KCS Integration on behalf of eb807814eed7d7ac93aa32dcc227fd7fc6036751 on Apr 20, 2018Last modified by Vishal Sharma on Jun 26, 2018
Version 2Show Document
  • View in full screen mode
Issue Description
You are following the SSO setup instructions provided by Azure to configure your IDP ( However, you are getting the error message: " Error processing SAML message. Request was ill-formed in some way. " To troubleshoot that message you are collecting the SAML assertion being passed to Marketo to identify potential issues with it (as described here: ). However, when trying to capture the SAML, you are not able to find any SAML in the network tracer even after arriving at the error message. 

Issue Resolution

Confirm the field "Sign on URL" is empty as it is only intended to be used for service provider initiated single sign-on, which is not supported by Marketo. 

Disclaimer: Marketo does not support 3rd party products such as Azure Active Directory and cannot configure your IDP on your behalf. This document is intended to assist Azure users in configuring their IDP, but no guarantees are made that this information is accurate.

Who This Solution Applies To
SSO users, Azure AD users

Is this article helpful ?