Can't sign in with SSO
Work through single sign-on (SSO) errors so Authors and admins can get back into the platform.
Symptom
You click your organization's sign-in button and one of the following happens:
- You land back on the login screen with no clear error, in a loop.
- You see a message such as "access denied," "no account found," or "your administrator has not granted access."
- SSO succeeds against your identity provider (for example, Microsoft Entra ID), but the platform reports that no matching Author account exists.
- Sign-in worked yesterday but suddenly fails for you or your whole team.
Likely causes
Ranked from most to least common:
- Your Author account isn't provisioned — the email from your identity provider doesn't match an active user in the platform.
- Email or attribute mismatch — SSO sends a different email/username than the one on file (for example, an alias or a changed domain).
- Not assigned to the SSO app — your admin hasn't granted you access to the application in Microsoft Entra ID (or another provider).
- Expired or changed connection — the SSO certificate, secret, or metadata expired or was rotated, which typically breaks sign-in for everyone at once.
- Stale session or browser state — cached tokens or cookies from a previous session.
Fixes
- Retry cleanly. Sign out fully, clear cookies for the site (or use a private window), then sign in again.
- Confirm the email. Check that the email your identity provider uses matches your Author account exactly. If it changed, ask your admin to update it.
- Ask your admin to check provisioning and assignment. Confirm your account is active and that you're assigned to the SSO application on the identity-provider side.
- Check for an expired connection. If sign-in fails for many users at once, the SSO certificate or secret has likely expired and your admin must renew it (confirm the exact steps in your account).
- Verify the provider is reachable. Rule out an outage or conditional-access policy blocking your device or location.
Still stuck?
Note the exact error text, the time, and your identity provider, then contact your platform administrator or support. A screenshot of the failure and the URL you were redirected to helps them diagnose it faster.
Related
Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.