> Source: [sk170119](https://support.checkpoint.com/results/sk/sk170119)

# sk170119 - In Harmony Connect, users connecting to the Internet receive "Could not login" message relating to the identity provider

| Property | Value |
|----------|-------|
| Solution ID | sk170119 |
| Date Created | 2020-11-01 |
| Last Modified | 2023-11-14 |
| Technical Level | General |

## Symptoms

- * Scenario 1 - Remote users

  1. Installed Harmony Connect Agent for Windows 10 or macOS
  2. Launched the app
  3. Entered a corporate email address (in some cases, the system fills this step automatically)
  4. A pop-up window appears with a request to enter a corporate sign-on password (in some cases, the user is automatically identified and does not need to enter the sign-on password)
  5. The pop-up window shows "`Could not log you in`" with an error code from the list below.
* Scenario 2 - Users in branch offices

  1. When a user connects to the Internet in a web browser, a response page asks the user to sign in with corporate credentials (in some cases, the system automatically fills this step)
  2. The web browser window shows "`Could not log you in`" with an error code from the list below.
* Possible error codes:

  * Error Code Number 1: '516c03168e73'
  * Error Code Number 2: '1b75bb048f42'
  * Error Code Number 3: '9v49f2db257b'
  * Error Code Number 4: '77d026ee27f6'
  * Error Code Number 5: 'c280f46927c7'
  * Error Code Number 6: '2a2f2011bb85'
  * Error Code Number 7: 'aa088f3577f'
  * Error Code Number 8: '33aa55ee282'
  * Error Code Number 9: '700ge3243a05'
  * Error Code Number 10: '6a49f2bb2172', '0aa35c235c91'

## Cause

The administrator can configure the authentication using a corporate Identity Provider. Some of the Identity Providers include Azure Active Directory, Microsoft Active Directory Federation Services, Okta, OneLogin, Ping, and G-Suite.

If an end user receives one of the error codes above, it is possible that the configuration that the system administrator made was incorrect.

## Solution

If you are an **end user**, contact your company administrator to configure the Identity Provider as required.

If you are an **administrator** , follow the instructions below based on the error code that your end user received. If the error persists, open a Support Ticket as described in [sk154712](https://support.checkpoint.com/results/sk/sk154712).

### Error Code Number 1, 2, and 3 - Missing Groups or User or UserId in SAML Response

> Set the following attributes in your Identity Provider configuration when you connect it to Check Point Harmony Connect:
>
> |----------------|------------------------|--------------------|--------------------|---------------------------------------|
> | Attribute Type | Claim Name in Azure AD | Claim Name in Okta | Claim Name in ADFS | Claim Name in OneLogin                |
> | **username**   | Name ID                | firstName lastName | Name ID            | NameID value email firstName lastName |
> | **groups**     | groups                 | groups             | Group              | groups                                |
> | **user id**    | objectidentifier       | userId             | primary_sid        | userID                                |
>
> For further explanation, see the [Harmony Connect Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Connect-Admin-Guide/Default.htm?cshid=identity_providers) \> Chapter "Settings" \> Section "Identity Provider Settings".

### Error Code Number 4 - Unencrypted Response

> In order for your Harmony Connect tenant to work with encrypted SAML Responses, this feature needs to be enabled by Check Point Support.
>
> If this is not the case, then open a Support Ticket as described in [sk154712](https://support.checkpoint.com/results/sk/sk154712).
>
> Otherwise, configure your Identity Provider to send only encrypted SAML responses to the Harmony Connect application.

### Error Code Number 5 - Incorrect Audience/EntityId

> In your Identity Provider, configure the Audience/EntityId to be the value that is given to you in Infinity Portal in the IDP configuration (EntityId in the "*A* *llow Connectivity*" tab).
>
> For further explanation, see the [Harmony Connect Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Connect-Admin-Guide/Default.htm?cshid=identity_providers) \> Chapter "Settings" \> Section "Identity Provider Settings".

### Error Code Number 6 - SAML Response clock is incorrect

> Check if the clock in your Identity Provider shows the correct time. If it does, and you are sure that the SAML Response that was sent by the user has not expired, open a Support Ticket as described in [sk154712](https://support.checkpoint.com/results/sk/sk154712).

### Error Code Number 7 - Incorrect Metadata file

> Download the federation metadata file from you Identity Provider based on the instructions for the Identity Provider that you are using.
>
> Import the XML file in Infinity Portal in the IDP configuration wizard (in the "*Configure Metadata*" tab).
>
> For further explanation, see the [Harmony Connect Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Connect-Admin-Guide/Default.htm?cshid=identity_providers) \> Chapter "Settings" \> Section "Identity Provider Settings".

### Error Code Number 8 - Wrong credentials

> Either the password or the username that was entered is incorrect.

### Error Code Number 9 - Empty SAML Response

> The SAML Response received was malformed (no data).

### Error Code Number 10 - General Error

> Open a Support Ticket as described in [sk154712](https://support.checkpoint.com/results/sk/sk154712).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
