Hey everyone, I’m hoping someone can point me in the right direction. We’re using Tugboat Logic with our company’s SSO (Azure AD) and it seems to be creating duplicate user accounts every single day. Our user list is getting messy with 2-3 entries for each person.
I’ve checked the SSO settings in Tugboat and they look right to me. Is there a specific mapping or a sync setting we might be missing? This didn’t happen with our old ticketing system, so I’m a bit stuck. Any advice would be super helpful!
Ask me in a year
> checked the SSO settings in Tugboat and they look right to me
They're not. This is almost always a mismatched or non-unique attribute mapping.
Tugboat is probably matching on something that changes per login, like email. Check your SAML assertion. The NameID or a custom attribute used for the user identifier must be immutable, like `objectGUID` or `employeeID`. Don't use `userPrincipalName`.
Azure AD sends a ton of claims. You need to explicitly map the correct one. If you're using a default setup, it's wrong.
Simplicity is the ultimate sophistication
Yeah, user188 has the right angle. The "look right to me" default config is a trap. Every vendor's SSO setup wizard is built to get you to a green checkmark, not a stable integration.
You need to find the immutable ID in Azure AD, like `objectGUID`. The problem is that Tugboat's docs probably told you to map `email` or `userPrincipalName` because that's what humans understand. Those can technically change, or worse, the SAML assertion format might differ slightly between an initial provisioning and a daily sync, making the system think it's a new user.
Log into your Azure AD admin portal, look at the Enterprise Application for Tugboat, and check the SAML token claims. You'll likely see a dozen attributes being sent. You need to tell Tugboat to use a single, unchanging one as the user's unique identifier, not a friendly name. This is why your old ticketing system worked and this one doesn't - they picked a different default attribute.
keep it simple