<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR | Azure AD Single Sign On Unauthorized. Unauthorized - 4010507 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-azure-ad-single-sign-on-unauthorized-unauthorized/m-p/1247117#M9077</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to setup SSO on my XDR tenant but I am getting the following message when login in&lt;BR /&gt;&lt;STRONG&gt;Unauthorized.&amp;nbsp;Unauthorized - 4010507&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the console "&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Management Audit Logs"&gt;Management Audit Logs" i see the below logs:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Custom Idp Saml User Invalid Error | invalid user: email address missing or misconfigured, please verify SAML attributes mapping&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I followed this video &lt;A href="https://www.youtube.com/watch?v=nwF3hY3wgc0" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.youtube.com/watch?v=nwF3hY3wgc0&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I verified the completed setup, all seems to be ok, but i can´t log in the tenant with SSO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me on this, thanks in advance.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jan 2026 13:49:20 GMT</pubDate>
    <dc:creator>G.Escobar</dc:creator>
    <dc:date>2026-01-30T13:49:20Z</dc:date>
    <item>
      <title>Cortex XDR | Azure AD Single Sign On Unauthorized. Unauthorized - 4010507</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-azure-ad-single-sign-on-unauthorized-unauthorized/m-p/1247117#M9077</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to setup SSO on my XDR tenant but I am getting the following message when login in&lt;BR /&gt;&lt;STRONG&gt;Unauthorized.&amp;nbsp;Unauthorized - 4010507&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the console "&lt;SPAN class="header-context-info"&gt;&lt;SPAN class="grid-header-left-side ng-star-inserted"&gt;&lt;SPAN class="grid-header-name-text ng-star-inserted" title="Management Audit Logs"&gt;Management Audit Logs" i see the below logs:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Custom Idp Saml User Invalid Error | invalid user: email address missing or misconfigured, please verify SAML attributes mapping&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I followed this video &lt;A href="https://www.youtube.com/watch?v=nwF3hY3wgc0" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.youtube.com/watch?v=nwF3hY3wgc0&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I verified the completed setup, all seems to be ok, but i can´t log in the tenant with SSO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me on this, thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 13:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-azure-ad-single-sign-on-unauthorized-unauthorized/m-p/1247117#M9077</guid>
      <dc:creator>G.Escobar</dc:creator>
      <dc:date>2026-01-30T13:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR | Azure AD Single Sign On Unauthorized. Unauthorized - 4010507</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-azure-ad-single-sign-on-unauthorized-unauthorized/m-p/1247119#M9079</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/773499587"&gt;@G.Escobar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error code &lt;STRONG&gt;Unauthorized - 4010507&lt;/STRONG&gt; indicates that the Cortex XDR platform received invalid or incomplete user data within the SAML assertion provided by your Identity Provider (IdP).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifically, the message &lt;STRONG&gt;“invalid user: email address missing or misconfigured”&lt;/STRONG&gt; means that the required email attribute expected by Cortex XDR was either not present in the SAML assertion or did not exactly match the attribute name mapping defined in the XDR console.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To resolve this issue, follow these troubleshooting steps:&lt;/P&gt;
&lt;H4&gt;1. Identify the Exact Attribute Name Using a SAML Tracer:&lt;/H4&gt;
&lt;P&gt;Because SAML attributes are case-sensitive and must match exactly, you must verify the raw data being sent by your IdP.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Install a browser extension such as &lt;STRONG&gt;SAML Tracer&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Open the tracer and reproduce the failed login attempt in an incognito window.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the tracer, locate the &lt;STRONG&gt;AttributeStatement&lt;/STRONG&gt; section within the SAML response.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Find the attribute that contains the user's email address and note the exact &lt;STRONG&gt;Name&lt;/STRONG&gt; value (for example, a URL or a simple string like &lt;CODE&gt;emailaddress&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;2. Update Attribute Mapping in Cortex XDR:&lt;/H4&gt;
&lt;P&gt;Once you have the exact attribute name from the SAML tracer, ensure it is configured correctly in the tenant:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Navigate to &lt;STRONG&gt;Settings → Configurations → Access Management → Single Sign-On&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Locate the &lt;STRONG&gt;IdP Attributes Mapping&lt;/STRONG&gt; section.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Ensure the &lt;STRONG&gt;Email&lt;/STRONG&gt; field contains the exact string identified in Step 1.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Common Azure AD Mapping:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;CODE&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Internal Note:&lt;/STRONG&gt;&lt;BR /&gt;In some instances, engineering has identified the correct mapping as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;CODE&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress/email&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;3. Verify the User Profile in Your IdP&lt;/H4&gt;
&lt;P&gt;The error can also occur if the user attempting to log in does not have an email address populated in their IdP profile.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Check the user's account in Azure AD (or your specific IdP) to ensure the email field is not empty.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Verify that the attribute you are mapping is actually the one containing the data (for example, mapping &lt;CODE&gt;user.mail&lt;/CODE&gt; vs &lt;CODE&gt;user.userprincipalname&lt;/CODE&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Summary of Common Azure AD Attribute Mappings&lt;/H4&gt;
&lt;P&gt;If you are using Azure AD, ensure these standard mappings are used (all case-sensitive):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;STRONG&gt;Email:&lt;/STRONG&gt; &lt;CODE&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;STRONG&gt;First Name:&lt;/STRONG&gt; &lt;CODE&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;STRONG&gt;Last Name:&lt;/STRONG&gt; &lt;CODE&gt;http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-unlink="true"&gt;&lt;STRONG&gt;Group Membership:&lt;/STRONG&gt; &lt;CODE&gt;http://schemas.microsoft.com/ws/2008/06/identity/claims/groups&amp;nbsp;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 13:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-azure-ad-single-sign-on-unauthorized-unauthorized/m-p/1247119#M9079</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-26T13:23:54Z</dc:date>
    </item>
  </channel>
</rss>

