Articles in this section

Single sign-on (SSO) login fails: common causes

Published:
Updated:

MobilityManager supports single sign-on (SSO) through OpenID Connect (OIDC) identity providers, including Azure AD (Microsoft Entra ID), Keycloak, ADFS, and generic OIDC. When the SSO button does not sign you in, the cause is usually a configuration mismatch at the company (tenant) level or a rejected identity token. This article lists the common causes and what to do.

Symptom

You select your company, click a button such as Login with Microsoft, and either no button appears, the provider returns an error, or you are bounced back with a failure message such as Identity provider token validation failed.

Common causes and resolutions

The SSO button does not appear

SSO is enabled per company. If the company you selected does not have OIDC turned on, only the email and password form is shown. Local login is always available; the SSO button only appears when SSO is enabled and configured for that company. If you expect SSO here, ask your administrator to enable and configure it.

The company's SSO configuration is incomplete

If you see OIDC is not configured for this tenant or OIDC configuration is incomplete for this tenant, the company is missing required settings such as the authority URL or client ID. An administrator must complete the OIDC configuration for that company.

The identity token is rejected

The message Identity provider token validation failed means the token returned by your provider did not pass validation. MobilityManager verifies the token's signature against the provider's published keys, along with its issuer, audience (your company's client ID), and expiry, and fails closed if any check does not pass. Typical causes include:

  • A client ID in MobilityManager that does not match the application registered at the provider (audience mismatch).
  • An authority or issuer URL that is wrong or unreachable, so the provider's discovery document and signing keys cannot be fetched.
  • A redirect URI that does not exactly match the one registered at the provider.
  • Clock skew beyond a few minutes between servers, causing a valid token to look expired.

These are administrator-side fixes. Report the exact message and the time it happened so the configuration can be checked against your provider.

Your email already belongs to a local account

If you see An account with this email already exists. Please contact your administrator to enable single sign-on for it., an existing account with a local password shares your email address. For safety, MobilityManager never silently links an external SSO identity to a local-password account. An administrator must link your identity provider subject to that account explicitly.

The licensed user limit is reached

New SSO users are provisioned automatically with the Driver role, but only if a licensed seat is available. If you see The licensed user limit has been reached. Please contact your administrator., the company is at its user cap. See the related article on seat and vehicle limits.

Note: A brand-new SSO user is created with the Driver role by default. If you need broader access after your first sign-in, an administrator assigns you an additional role.

Related

  • I cannot log in: a step-by-step checklist
  • I reached a seat or vehicle limit
  • "Access Denied": understanding permissions and roles
  • A company (tenant) is not showing at login
AH
Written by Alexander Hagemann
Updated:
Access denied
Access denied