Users are being challenged for credentials and the following message appears in the SiteMinder Policy Server audit logs:
"Status: Not Authorized. Session is not authorized for this security level"
A session's authentication level is determined by the authentication scheme used when the user first logs into a protected SiteMinder (Single Sign-on) resource.
This log message:
"Status: Not Authorized. Session is not authorized for this security level"
indicates the user has a valid session, but it was established at a security level lower than the protected resource the user is now trying to access.
If this is unexpected, review where the user first logged in and adjust the security level of that authentication scheme.