NameID issue during webex + DUO + Azure SSO integration

I’m trying to enable DUO SSO for webex (Conrtol Hub). Azure AD is configured as authentication source.
I made all steps according to this guide But when I test SSO on Control Hub page I see such error: Cannot create NameID. Source attribute ‘Email’ does not exist.
At the same time I see logs about successful login to webex in DUO and Azure admin panels. Moreover DUO creates a new user.
Seems that something wrong with NameID format or attributes. In Azure nameID format uses user.mail: NameID Format=“urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress”

In SAML tracer I see that webex sends nameID in transient format: Format=“urn:oasis:names:tc:SAML:2.0:nameid-format:transient”
Also in SAML tracer I see that correct Email attribute is sending as webex expects: Attribute Name=“”>

I opened case to webex and DUO team but everybody told me that everything was Ok from their side.
I read appropriate topic on the DUO KB and checked configuration many times, but issue is still here.

I would appreciate everyone who can help solve this issue. Thanks!

I found your Duo support case and noted that you were also asking the community.

I saw you sent them a screenshot of your Azure claims.

It looks like instead of naming the claim with just the attribute name (like Email) the claim names are a url (like Did you try to log in with the five claim names configured so they match what’s shown in the example here?

1 Like

Kristina many thanks for your idea! It works!
The problem was that I used the default settings of claim format which contains namespace (like

I removed these default claims and created the new ones.

I am very grateful that you responded!

1 Like

Glad that helped you get this working.