SSO Login Degradation: OneLogin SAML & OIDC

Incident Report for StrongDM

Resolved

This issue has now been resolved.

SAML: The app login URL should not include a trailing slash.

OIDC: OneLogin reverted the changes to OIDC authentication behavior, no further changes are required.
Posted Jun 16, 2025 - 17:55 UTC

Update

We are continuing to investigate this issue.
Posted Jun 16, 2025 - 17:47 UTC

Update

We are continuing to investigate this issue.
Posted Jun 16, 2025 - 17:46 UTC

Investigating

We are currently investigating an authentication issue affecting some users logging in via OneLogin SSO at app.strongdm.com and the StrongDM GUI client.

SAML: A recent change from OneLogin appears to impact SAML logins. As a workaround, remove the trailing slash from the Login URL in your StrongDM application settings within OneLogin. This restores login functionality for most SAML users.

OIDC: A recent change from OneLogin appears to impact OIDC logins. OneLogin has reverted the change. No further action is required.
Posted Jun 16, 2025 - 15:47 UTC
This incident affected: US Control Plane (Admin UI), UK Control Plane (Admin UI), and EU Control Plane (Admin UI).