### Steps to reproduce
1. Login using LDAPUser
2. Connects fine
3. Go into …apps and enable User_SAML
4. Connect to NextCloud and get forwarded to IDP for login
5. Login using same account
6. Get error: Account not provisioned. Your account is not provisioned, access to this service is thus not possible.
### Expected behaviour
SSO & SAML authentication not working using Microsoft AD FS 2022 iDP. LDAP authentication works correctly
Error when logging in Account not provisioned
```
**Operating system**:Ubuntu 22.04
**Web server:**nginx version : 1.18.0
**Database:** MariaDB 10.6.12
**PHP version:** 8.1
**Nextcloud version:** 25.0.6
```
**List of activated apps:**
```
Enabled:
- activity: 2.17.0
- admin_audit: 1.15.0
- bruteforcesettings: 2.5.0
- circles: 25.0.0
- cloud_federation_api: 1.8.0
- comments: 1.15.0
- contacts: 5.2.0
- contactsinteraction: 1.6.0
- dav: 1.24.0
- federatedfilesharing: 1.15.0
- federation: 1.15.0
- files: 1.20.1
- files_pdfviewer: 2.6.0
- files_rightclick: 1.4.0
- files_sharing: 1.17.0
- files_trashbin: 1.15.0
- files_versions: 1.18.0
- forms: 3.2.0
- groupfolders: 13.1.3
- guests: 2.4.0
- logreader: 2.10.0
- lookup_server_connector: 1.13.0
- nextcloud_announcements: 1.14.0
- notifications: 2.13.1
- oauth2: 1.13.0
- onlyoffice: 7.8.0
- password_policy: 1.15.0
- passwords: 2023.5.30
- photos: 2.0.1
- privacy: 1.9.0
- provisioning_api: 1.15.0
- recommendations: 1.4.0
- related_resources: 1.0.4
- serverinfo: 1.15.0
- settings: 1.7.0
- sharebymail: 1.15.0
- socialsharing_email: 2.6.0
- spreed: 15.0.5
- support: 1.8.0
- survey_client: 1.13.0
- systemtags: 1.15.0
- text: 3.6.0
- theming: 2.0.1
- twofactor_admin: 4.1.9
- twofactor_backupcodes: 1.14.0
- twofactor_totp: 7.0.0
- user_ldap: 1.15.0
- user_saml: 5.1.2
- user_status: 1.5.0
- viewer: 1.9.0
- workflowengine: 2.7.0
```
**Nextcloud configuration:**
```
php occ config:list system
{
"system": {
"instanceid": "***REMOVED SENSITIVE VALUE***",
"passwordsalt": "***REMOVED SENSITIVE VALUE***",
"secret": "***REMOVED SENSITIVE VALUE***",
"trusted_domains": [
"web01.removed.loc",
"web02.removed.loc",
"haproxy01.removed.loc",
"haproxy01.removed.loc",
"REMOVED SENSITIVE VALUE"
],
"trusted_proxies": "***REMOVED SENSITIVE VALUE***",
"overwriteprotocol": "https",
"overwritehost": "REMOVED SENSITIVE VALUE",
"overwritecondaddr": [
"^10\\.99\\.35\\.30$",
"^10\\.99\\.35\\.31$",
"^10\\.99\\.35\\.32$",
"^REMOVED \\.SENSITIVE \\.VALUE$"
],
"overwrite.cli.url": "https:\/\/nextcloud.domain.name",
"default_phone_region": "RU",
"default_language": "ru",
"default_locale": "ru_RU",
"datadirectory": "***REMOVED SENSITIVE VALUE***",
"dbtype": "mysql",
"version": "25.0.6.1",
"dbname": "***REMOVED SENSITIVE VALUE***",
"dbhost": "***REMOVED SENSITIVE VALUE***",
"dbport": "",
"dbtableprefix": "oc_",
"mysql.utf8mb4": true,
"dbuser": "***REMOVED SENSITIVE VALUE***",
"dbpassword": "***REMOVED SENSITIVE VALUE***",
"installed": true,
"maintenance": false,
"memcache.local": "\\OC\\Memcache\\Redis",
"redis": {
"host": "***REMOVED SENSITIVE VALUE***",
"port": 26379
},
"ldapProviderFactory": "OCA\\User_LDAP\\LDAPProviderFactory",
"app_install_overwrite": [
"documentserver_community",
"twofactor_admin"
],
"onlyoffice": {
"verify_peer_off": "true",
"jwt_header": "AuthorizationJwt"
},
"theme": "",
"loglevel": 4,
"debug": true,
"log.condition": {
"apps": [
"admin_audit",
"workflowengine"
]
},
"twofactor_enforced": "false",
"twofactor_enforced_groups": [],
"twofactor_enforced_excluded_groups": [
"test"
],
"remember_login_cookie_lifetime": 86400,
"session_lifetime": 43200,
"mail_smtpmode": "smtp",
"mail_smtphost": "***REMOVED SENSITIVE VALUE***",
"mail_sendmailmode": "smtp",
"mail_smtpport": "25",
"mail_from_address": "***REMOVED SENSITIVE VALUE***",
"mail_domain": "***REMOVED SENSITIVE VALUE***"
```
### Client configuration
**Browser:** Google Chrome 113.0.5672.92
**Operating system:**MS Windows 10 Pro 21H2
### Logs
#### Nextcloud log (data/owncloud.log)
```
IDP parameter for the UID not found. Possible parameters are: []
```
#### Browser log
```
### In Chrome Developer Tools the following SAMLResponce data:
<samlp:Response ID="_5cb7817a-ee03-4190-b4e5-ac1e30cc35d1" Version="2.0" IssueInstant="2023-05-11T03:05:10.623Z" Destination="https://nextcloud/index.php/apps/user_saml/saml/acs" Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified" InResponseTo="ONELOGIN_ad6a24cdd9f93643a669696bb15791d1d705f8fb" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol">
<Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">http://ADFS/adfs/services/trust</Issuer>
<samlp:Status>
<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status>
<Assertion ID="_8540e7de-978b-42ba-95c3-ec477acca4c3" IssueInstant="2023-05-11T03:05:10.623Z" Version="2.0" xmlns="urn:oasis:names:tc:SAML:2.0:assertion">
<Issuer>http://ADFS/adfs/services/trust</Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#_8540e7de-978b-42ba-95c3-ec477acca4c3">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>EcuCsu6mbeXLd25n5DAmY6+gGsKuRJuxmqbnngeccL8=</ds:DigestValue>
</ds:Reference></ds:SignedInfo>
<ds:SignatureValue>rzqD...</ds:SignatureValue>
<KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data><ds:X509Certificate>MIIE3..</ds:X509Certificate></ds:X509Data>
</KeyInfo></ds:Signature>
<Subject>
<NameID>my_sAMAccountName</NameID> - Correct
<SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<SubjectConfirmationData InResponseTo="ONELOGIN_ad6a24cdd9f93643a669696bb15791d1d705f8fb" NotOnOrAfter="2023-05-11T03:10:10.623Z" Recipient="https://nextcloud/index.php/apps/user_saml/saml/acs"/>
</SubjectConfirmation></Subject>
<Conditions NotBefore="2023-05-11T03:05:09.998Z" NotOnOrAfter="2023-05-11T04:05:09.998Z">
<AudienceRestriction>
<Audience>https://nextcloud/index.php/apps/user_saml/saml/metadata</Audience>
</AudienceRestriction></Conditions>
<AuthnStatement AuthnInstant="2023-05-11T03:03:21.825Z" SessionIndex="_8540e7de-978b-42ba-95c3-ec477acca4c3">
<AuthnContext>
<AuthnContextClassRef>urn:federation:authentication:windows</AuthnContextClassRef>
</AuthnContext></AuthnStatement></Assertion></samlp:Response>
```
### Settings iDP:
![1](https://github.com/nextcloud/user_saml/assets/132979697/7a4abf85-b09d-448c-b1f8-c36477e1535e)
### Settings LDAP
Internal Username Attribute: sAMAccountName
### Settings user_saml
![4](https://github.com/nextcloud/user_saml/assets/132979697/454bdad3-3d17-468f-abac-84db59c25103)
Used many options for specifying attributes: userPrincipalName, UPN, NameIdentifier