Error: AADSTS900561 When Authenticating to PAM With Entra ID SAML
search cancel

Error: AADSTS900561 When Authenticating to PAM With Entra ID SAML

book

Article ID: 449899

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

When performing a SAML login into Privileged Access Manager (PAM) with Microsoft Entra ID (formerly Azure AD), the following error is observed in Azure. The error occurs only when using the PAM Client, browser logins are successful.

AADSTS900561: The endpoint only accepts POST requests. Received a GET request.

Environment

PAM 4.3.1 and below with Entra ID SAML integration

Cause

The PAM Client uses an embedded Chromium-based browser. By default, Chromium does not transmit device state or PRT information to Microsoft identity services. If the Entra ID is configured to block specific operating systems or browsers, it will block authentication from the PAM client due to the lack of information.

Resolution

The code was fixed as DE683110 in the 4.3.2 release, upgrade to 4.3.2 to resolve the issue.

Additional Information

If you observe this problem and it doesn't fix itself as described above, contact Support.