Hi,
Totally new issue for me. In our system (8.2 on premise) I created a new user without any noticeable errors. When the user starts her browser, she navigates to https://ourorganizationurl and gets to logon ADFS. After pressing the [logon] button, she receives a message stating that either her account is disabled or the business unit is disabled.
Both are active. BUT! In the URL of the error message I noticed it stated "The user with SystemUserId 658fcd68-251c-e611-80cd-02bfac10284b in OrganizationContext 0cf95118-02ed-e511-80c5-02bfac10284b is disabled"
The orginazation id is correct, but the userid IS NOT HERS (spooky, huh?).
The systemuserid in the URL is the one of a former colleague who has left us long time ago. Even his AD isn't active anymore. The only link is that they have exactly the same emailaddress. Before creating the new user, I cleared the emailaddress in the deactivated former colleague hoping to prevent problems. Unfortunately that didn't do the trick.
It looks as if ADFS provides the systemuserid of our former colleague out of a (at least three year old) caching or so. Doesn't make sense, but maybe to you?
Any thoughts on how to solve this?
thanks, regards,
Jeroen