Skip to main content

Can't sign in with SSO

Work through single sign-on (SSO) errors so Authors and admins can get back into the platform.

Symptom

You click your organization's sign-in button and one of the following happens:

  • You land back on the login screen with no clear error, in a loop.
  • You see a message such as "access denied," "no account found," or "your administrator has not granted access."
  • SSO succeeds against your identity provider (for example, Microsoft Entra ID), but the platform reports that no matching Author account exists.
  • Sign-in worked yesterday but suddenly fails for you or your whole team.

Likely causes

Ranked from most to least common:

  1. Your Author account isn't provisioned — the email from your identity provider doesn't match an active user in the platform.
  2. Email or attribute mismatch — SSO sends a different email/username than the one on file (for example, an alias or a changed domain).
  3. Not assigned to the SSO app — your admin hasn't granted you access to the application in Microsoft Entra ID (or another provider).
  4. Expired or changed connection — the SSO certificate, secret, or metadata expired or was rotated, which typically breaks sign-in for everyone at once.
  5. Stale session or browser state — cached tokens or cookies from a previous session.

Fixes

  1. Retry cleanly. Sign out fully, clear cookies for the site (or use a private window), then sign in again.
  2. Confirm the email. Check that the email your identity provider uses matches your Author account exactly. If it changed, ask your admin to update it.
  3. Ask your admin to check provisioning and assignment. Confirm your account is active and that you're assigned to the SSO application on the identity-provider side.
  4. Check for an expired connection. If sign-in fails for many users at once, the SSO certificate or secret has likely expired and your admin must renew it (confirm the exact steps in your account).
  5. Verify the provider is reachable. Rule out an outage or conditional-access policy blocking your device or location.

Still stuck?

Note the exact error text, the time, and your identity provider, then contact your platform administrator or support. A screenshot of the failure and the URL you were redirected to helps them diagnose it faster.


Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.