Problem:
When a federated user logs in to a Privileged Service Resource using an account that is local to the resource, the error appears: Authentication (login or callenge) has failed. Please try again or contact your system administrator.
Cause:
The authentication profile for the federated user is set to use a password on login. Since the users belongs to the federated domain, the password is unknown to the tenant, therefore the authentication fails.
Resolution:
Passsword requirement in authentication profiles for federated users is not supported. Authentication profiles for federated users are dependent on the type of data that is provided by the federated domain. This may or may not include phones numbers and emails. Federated user may or may not be allowed to do security questions or OATH authenticators. External radius may or may not work for a federated user. While these other mechanisms could potentially work, it is by design that a password requirement in the profile will not work.