This article addresses an authentication conflict observed in federation journeys where a double login prompt appears—once at the Identity Provider (IdP) and again at the Service Provider (SP) hosted on an Identity Manager (IdM) Virtual Appliance (VAPP).
Identity Manager 14.5
Siteminder 12.8
The double authentication prompt occurs because both the Identity Provider and the Service Provider are enforcing SiteMinder protection policies simultaneously. When the IdP completes authentication, the SP environment re-triggers its own authentication challenge, creating a redundant login step for the user.
Analyze Protection Policies: Verify that the VAPP Service Provider environment is configured to accept the assertions provided by the IdP without initiating its own internal authentication challenge.
Disable Redundant Protection: Modify the site protection settings on the Service Provider (SP) side to trust the incoming federation assertion. Disable the SiteMinder protection specifically for the SP-hosted resources that are protected by the federation flow.
Validate Federation Flow: After applying changes, clear browser cookies and test the federation journey. The user should authenticate once at the IdP, and the SP should consume the assertion directly without prompting for a second login.
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.