Skip to main content

Common SSO Errors

Only IT Admin users can view SSO Logs

Under Settings > Security > SSO Logs, IT Admins can view successful and failed SSO logins via the App and Portal. The App is the main Clipboard product and is accessed by staff at your school who have been added as users in Clipboard. The Portal is our student/parent portal with a personalised student/parent calendar and Activity Selection and is only accessed by students and their guardians in Clipboard via SSO.

Successful SSO Logins will show the following:

  • User

  • Product (App or Portal)

  • Timestamp

  • Status (Success or Error)

Failed SSO Logins will show the above as well as showing important information for the error, such as:

  • Mapping Attempted

  • SAML Response

  • Attributes

Below you will find the list of reasons SSO might fail and how to resolve them!

Error: Deactivated User

  • App - the user attempting to log in has been deactivated.

  • Portal - a student is not current in your SIS, and therefore they and their guardians are not current in Clipboard.

    • If the student and their guardians have been incorrectly made non-current, this information will need to be changed in your SIS and updated via integration syncs.

Error: Mapping Not Found

  • App - the SAML Attribute used for Property Mapping staff was not returned in the SAML Response.

    • In most cases, user.mail is recommended to be used as the SAML Attribute name.

  • Portal - the SAML Attribute used for Property Mapping students and guardians was not returned in the SAML Response.

    • In most cases, name.id or user.mail is recommended to be used as the SAML Attribute name.

  • IT Admin can check the logs to determine what attributes and SAML Responses were used in the unsuccessful login attempt.

Top Tip: 'None' can be used for Property Mapping guardians if the SAML Attribute is the same as students!

Error: User Not Found

  • App - staff has not been added to the App. All school staff who need to use Clipboard will need to be manually added.

    • Check that school staff have been added to Clipboard in the Staff List. If they haven't, follow our help article on Adding Users.

  • App - staff are attempting to log in using a different email address than the one stored on their profile in Clipboard and your SSO server.

    • Check they are using the correct email address.

  • Portal - staff may be trying to sign into the Portal. Only students and their guardians in Clipboard can access the Portal.

    • Ensure users are logging in via the Login URL for the App or via go. clipboard.app.

  • Portal - a student or their guardian(s) are not in Clipboard and, therefore, can't access the Portal.

    • Here is our article explaining the causes of Missing Students in Clipboard and how to resolve them. Similarly, check that you are pulling the data from your SIS for missing guardians.

  • Portal - guardians are attempting to log in using a different email address than the one stored in Clipboard and your SSO server.

    • Check they are using the correct email address.

    • If they have a different email address in Clipboard to the one needed for SSO login, their SSO email address needs to be stored in Clipboard as an external username, or instead, the guardians need to be mapped to Parent SIS ID.

    • In most cases, name_id is recommended as the SAML Attribute name.

  • Portal - guardian SAML Attribute Name may be incorrect. If you use Azure, try the full schema URL.

Top Tip: Check that your users have been added to your SSO server!

Error: Assertion Failed

  • App and Portal - we received an incorrect SAML Response from your SSO server.

    • Check the metadata URL is up to date.

    • Check that the SSO server has been configured correctly.

Error: Certificate Expired

Clipboard has introduced an automatic SSO Metadata refresh, which schedules a service to refresh the metadata URL. Therefore, this error should not occur for a Metadata URL, as it will automatically refresh. However, if you do get this message because you have uploaded a file instead, it means that your App and Portal school certificate has expired. Please do the following to refresh it:

  • Check that any updated or renewed certificates match the information in Clipboard.

  • This can be updated by going to Configure SSO in Clipboard and re-entering your metadata URL.

  • For the Portal, the metadata does not match between the Clipboard and your SSO server.

    • Check that your metadata is in Clipboard correctly and our metadata is in your SSO server correctly.

      If you are still experiencing this error, please contact [email protected]

Error: More Than One User Found

  • App - two or more users were found with the same email address in Clipboard.

    • Look in the Staff List for any duplicate profiles. If any are found, either deactivate one profile or change the email address.

  • Portal - non-unique attribute used.

    • Check the custom attributes used to map guardians.

    • In most cases, name_id is recommended as the SAML Attribute name.

  • Portal - two or more guardians have the same data.

    • Check that there are no guardians with the same external username, Parent SIS ID etc.

Error: Response Not Yet Valid – Check IdP ClockApp & Portal

The SAML assertion arrived with a Not Before timestamp that is a few seconds in the future compared with Clipboard’s server time.


Fix:

  1. Ask your IT team to verify that the SSO / IdP server’s system clock is correctly synced to a reliable NTP source (e.g. pool.ntp.org, time.windows.com).

  2. Once the IdP clock is within a few seconds of UTC, retry the login – the error should disappear.

(Tip: Clipboard accepts assertions up to five seconds early. Anything beyond that will trigger this error.)

Did this answer your question?