on
11 Nov 2025
12:13 AM
- edited on
26 Nov 2025
02:48 PM
by
Michal_Gebacki
This article refers to the Dynatrace Account Management platform and addresses issues related to SSO login failures caused by invalid SAML signatures. It provides detailed steps to resolve login issues when the SAML certificate has expired or is mismatched between the Identity Provider (SSO) and Dynatrace.
In this example, the Identity Provider is Azure Active Directory (Azure AD).
Users are unable to log in using SSO. The error message displayed is:
400
Request denied!
SAML Message was signed by invalid Signature.
Please check certificates appended to SAML Metadata and your SAML Signing settings.
Root Cause:
Once the above steps are performed, the affected users can log in successfully using SSO. The process will renew the certificate configured on Dynatrace and sync Azure AD with Dynatrace.
If this article did not help, please:
Open a support ticket and include:
Alternative Actions: Refer to Dynatrace documentation and common SAML troubleshooting resources: