IBM Support

"Cannot create Account object" after logging in to ADFS OIDC namespace

Troubleshooting


Problem

After logging in to an ADFS namespace and being redirected back to Cognos, the authentication fails with the following error: Cannot create Account object

Cause

The specified unique identifier is not recognized by Cognos.

Resolving The Problem

Either use a recognized Content Manager account object (such as email) in the Unique Identifier property, or configure a custom property for the desired value.
For example, if the ADFS returns UPN in the ID Token and you want to use UPN as the Unique Identifier, do the following:
- In the namespace configuration, find the Custom Properties setting and click Edit
- Click Add
- Enter the following name/value combination:
Name: upn
Value: upn
- Click OK
- Set the Unique Identifier value to: upn
- Click Save

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSTSF6","label":"IBM Cognos Analytics"},"Component":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"11.1.x","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
30 May 2019

UID

ibm10886191