tomcat_sandbox1 | 2019-12-11 00:02:53,348 DEBUG [org.pac4j.saml.transport.Pac4jHTTPRedirectDeflateEncoder] - <Building URL to redirect client to>
tomcat_sandbox1 | 2019-12-11 00:02:53,349 DEBUG [org.apereo.cas.web.DelegatedClientNavigationController] - <Determined final redirect action for client [#SAML2Client# | name: Microsoft Account | callbackUrl: https://example.com:8081/cas/login | urlResolver: org.pac4j.core.http.url.DefaultUrlResolver@24b485e | callbackUrlResolver: org.pac4j.core.http.callback.QueryParameterCallbackUrlResolver@7c75b203 | ajaxRequestResolver: org.pac4j.core.http.ajax.DefaultAjaxRequestResolver@2309065f | redirectionActionBuilder: org.pac4j.saml.redirect.SAML2RedirectionActionBuilder@4ff985a6 | credentialsExtractor: org.pac4j.saml.credentials.extractor.SAML2CredentialsExtractor@17282dbf | authenticator: org.pac4j.saml.credentials.authenticator.SAML2Authenticator@461c60f3 | profileCreator: org.pac4j.core.profile.creator.AuthenticatorProfileCreator@60c19035 | logoutActionBuilder: org.pac4j.saml.logout.SAML2LogoutActionBuilder@2dccbd91 | authorizationGenerators: [] |] as [#HttpAction# | code: 302 |]>
tomcat_sandbox1 | 2019-12-11 00:02:53,349 DEBUG [org.apereo.cas.web.DelegatedClientNavigationController] - <Redirecting client [Microsoft Account] to [https://login.microsoftonline.com/f8f35f5d-1f7b-4427-90f7-f4565c5177aa/saml2?SAMLRequest=hVLLbtswELz3KwReCz0oS5ZMWDLUB...opHyP7Xahv9qK8%2FP970t%2FwA%3D&RelayState=https%3A%2F%2Fexample.com%3A8081%2Fcas%2Flogin%3Fclient_name%3DMicrosoft%2BAccount] based on identifier [TST-17-QGT8LfgkBi3VsxEvwN42Y0nJKM8bFc4F]>
tomcat_sandbox1 | 2019-12-11 00:03:00,218 DEBUG [org.apereo.cas.services.AbstractServicesManager] - <Adding registered service [https://example.com:8081/app\?client_name=CasClient] with name [My App] and internal identifier [8081]>
tomcat_sandbox1 | 2019-12-11 00:03:00,218 INFO [org.apereo.cas.services.AbstractServicesManager] - <Loaded [1] service(s) from [JsonServiceRegistry].>
tomcat_sandbox1 | 2019-12-11 00:03:10,094 INFO [org.apereo.cas.ticket.registry.DefaultTicketRegistryCleaner] - <[0] expired tickets removed.>
tomcat_sandbox1 | 2019-12-11 00:03:10,094 DEBUG [org.apereo.cas.ticket.registry.DefaultTicketRegistryCleaner] - <Finished ticket cleanup.>
tomcat_sandbox1 | 2019-12-11 00:04:00,221 DEBUG [org.apereo.cas.services.AbstractServicesManager] - <Adding registered service [https://example.com:8081/app\?client_name=CasClient] with name [My App] and internal identifier [8081]>
tomcat_sandbox1 | 2019-12-11 00:04:00,221 INFO [org.apereo.cas.services.AbstractServicesManager] - <Loaded [1] service(s) from [JsonServiceRegistry].>
tomcat_sandbox1 | 2019-12-11 00:04:32,742 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Client identifier could not found as part of the request parameters. Looking at relay-state for the SAML2 client>
tomcat_sandbox1 | 2019-12-11 00:04:32,742 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Located delegated client identifier for this request as [Optional[https://example.com:8081/cas/login?client_name=Microsoft+Account]]>
tomcat_sandbox1 | 2019-12-11 00:04:32,743 ERROR [org.apereo.cas.web.DelegatedClientWebflowManager] - <Delegated client identifier cannot be located in the authentication request [https://example.com:8081/cas/login?client_name=Microsoft+Account]>
tomcat_sandbox1 | 2019-12-11 00:04:32,742 DEBUG [org.apereo.cas.ticket.registry.AbstractMapBasedTicketRegistry] - <Ticket [https://example.com:8081/cas/login?client_name=Microsoft+Account] could not be found>
tomcat_sandbox1 | 2019-12-11 00:04:47,247 DEBUG [org.pac4j.saml.transport.Pac4jHTTPRedirectDeflateEncoder] - <Building URL to redirect client to>
tomcat_sandbox1 | 2019-12-11 00:04:47,247 DEBUG [org.apereo.cas.web.DelegatedClientNavigationController] - <Determined final redirect action for client [#SAML2Client# | name: Microsoft Account | callbackUrl: https://example.com:8081/cas/login | urlResolver: org.pac4j.core.http.url.DefaultUrlResolver@24b485e | callbackUrlResolver: org.pac4j.core.http.callback.QueryParameterCallbackUrlResolver@7c75b203 | ajaxRequestResolver: org.pac4j.core.http.ajax.DefaultAjaxRequestResolver@2309065f | redirectionActionBuilder: org.pac4j.saml.redirect.SAML2RedirectionActionBuilder@4ff985a6 | credentialsExtractor: org.pac4j.saml.credentials.extractor.SAML2CredentialsExtractor@17282dbf | authenticator: org.pac4j.saml.credentials.authenticator.SAML2Authenticator@461c60f3 | profileCreator: org.pac4j.core.profile.creator.AuthenticatorProfileCreator@60c19035 | logoutActionBuilder: org.pac4j.saml.logout.SAML2LogoutActionBuilder@2dccbd91 | authorizationGenerators: [] |] as [#HttpAction# | code: 302 |]>
tomcat_sandbox1 | 2019-12-11 00:04:47,248 DEBUG [org.apereo.cas.web.DelegatedClientNavigationController] - <Redirecting client [Microsoft Account] to [https://login.microsoftonline.com/f8f35f5d-1f7b-4427-90f7-f4565c5177aa/saml2?SAMLRequest=hVLLbtswELz3KwReCz0tRRJhyVAbBDWQtEas9NBLQF...6nV1v9XW3l%2Bvu9t%2BQc%3D&RelayState=TST-18-wFsg-mhj51LmwtQ9t5hEghvgEGCtbfhO] based on identifier [TST-18-wFsg-mhj51LmwtQ9t5hEghvgEGCtbfhO]>
tomcat_sandbox1 | 2019-12-11 00:04:47,722 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Client identifier could not found as part of the request parameters. Looking at relay-state for the SAML2 client>
tomcat_sandbox1 | 2019-12-11 00:04:47,722 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Located delegated client identifier for this request as [Optional[TST-18-wFsg-mhj51LmwtQ9t5hEghvgEGCtbfhO]]>
tomcat_sandbox1 | 2019-12-11 00:04:47,722 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Located delegated client identifier as [TST-18-wFsg-mhj51LmwtQ9t5hEghvgEGCtbfhO]>
tomcat_sandbox1 | 2019-12-11 00:04:47,722 DEBUG [org.apereo.cas.web.DelegatedClientWebflowManager] - <Removing delegated client identifier [TST-18-wFsg-mhj51LmwtQ9t5hEghvgEGCtbfhO] from registry>
I replied to the wrong thread, below was meant for this not the OIDC thread..