Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
First determine whether the failure affects many users and applications or only one person or service. Check your identity provider’s status, then use sign-in logs and the point where the login fails to distinguish a provider incident from an MFA, SAML, account-assignment, application, or network problem. Record evidence before changing configuration.
1. Establish the scope and check provider status
Ask when the failures began, which people are affected, and whether they occur across multiple applications that use the same identity provider (IdP). A sudden problem spanning users and apps makes a provider incident more plausible; a failure isolated to one app or person points toward a narrower cause. Neither pattern proves the cause on its own.
- Check the provider’s public status page and incident notices. For previously working sign-ins that suddenly fail, OpenAI’s official SSO guidance recommends checking service status before changing IdP or network settings.
- If you use Okta, its Admin Console status section reports cell performance. “Operational,” “Degradation,” and “Failed to load” are different results: “Failed to load” means the status retrieval failed, not that an outage has been confirmed. Refresh or check the public status source.
- Note the time the issue started and whether the affected users share an app, group, location, network, or authentication policy.
A login error that mentions the IdP is not, by itself, evidence of an IdP-wide outage.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →2. Capture sign-in evidence before changing settings
Use the IdP’s sign-in logs to find a failed attempt for an affected user or application. In Microsoft Entra, filter sign-in logs by user or application and select failed sign-ins. Read the failure reason and additional details before changing a policy: documented causes include incomplete MFA, invalid credentials, an internal retry allowance, and an expired session or reauthentication check.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Save the details that will let an administrator or support engineer identify the exact attempt:
- Timestamp, including time zone
- Affected username, user ID, and sign-in identifier
- Application and whether other users or apps are affected
- Error text, sign-in error code, failure reason, and correlation ID
- Whether the failure occurred before MFA, during MFA, or after the user returned from the IdP
Keep passwords, session cookies, access tokens, and other secrets out of tickets and screenshots. Microsoft Entra’s troubleshooting guidance notes that the failure reason describes the error and additional details often explain how to resolve it.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. Identify where the login fails
Separate the authentication step from the application’s decision to accept the resulting token or assertion. A user can authenticate successfully at the IdP and still be denied by the application after the IdP returns the sign-in response.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems| Observed failure | What it may indicate | Useful evidence |
|---|---|---|
| Before the IdP accepts the user’s credentials | Credentials, account state, sign-in policy, or a broader IdP problem | IdP sign-in log, error code, failure reason, provider status |
| At the MFA prompt | Enrollment, factor availability, or delivery problem | Log details, factor used, whether another approved factor is available |
| After the IdP reports success, on the application’s page | The application may reject the returned assertion or token, or the user may lack access | IdP log, SAML response details where applicable, application log |
| Only in a particular browser or network | A stale session or a network control may be interrupting the authentication flow | Approved private-session test, network path, proxy or firewall details |
For SAML, Microsoft’s test guidance describes a successful sign-in as Entra issuing a SAML response that the application uses to sign the user in. If the IdP issues the response but the application displays an error, investigate the application’s acceptance of it rather than assuming the IdP authentication failed.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
4. For SAML failures, check the request and response
Compare the values on both sides of the exchange. Start with the error and SAML request, then inspect the response if it reaches the application.
- Destination: The request destination should match the IdP’s SSO service URL.
- Issuer: The issuer should match the application identifier configured in the IdP.
- Assertion Consumer Service (ACS) URL: The request or IdP configuration must use the endpoint the application expects.
- Response contents: If the application rejects a response, check the NameID value and format, claims, and signing certificate against the application’s requirements.
AWS IAM Identity Center gives a concrete example of strict matching: the NameID must match an existing username, and the ACS URL configured at the external IdP must match the service URL. Its guidance points administrators to the CloudTrail ExternalIdPDirectoryLogin event when investigating external-IdP sign-in failures. If the response still does not yield a login, ask the application vendor which field or claim it requires.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
5. Check whether the user is assigned and mapped correctly
If only certain people fail, verify that each affected person has an account in the target service, is provisioned there, and is assigned to the correct application or group. Also compare the identity the IdP sends—often a username or email address—with the identifier the application expects.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Authentication and authorization are separate: the IdP can confirm who someone is while the service denies access because the account is absent, not a member of the right group, or mapped to a different identity. AWS IAM Identity Center does not create users just in time through SAML federation; users must be pre-created or provisioned.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
For an OpenAI workspace access issue, its SSO troubleshooting guidance directs administrators to check IdP app assignment, workspace invitation or membership, SCIM group assignment or sync, and email mapping. These are useful checks whenever the IdP authenticates a user but the expected service or workspace remains unavailable.
6. Treat MFA, browser, and network issues as separate branches
If the failure is at MFA
Check whether the user completed enrollment and whether the configured factor is available. If the problem is delayed email delivery and the IdP itself is operational, an already enrolled, organization-approved alternative such as Okta Verify, a security key, or SMS may help. An alternate factor cannot restore an unavailable IdP, and users should not be instructed to bypass organizational sign-in policy.
If the failure appears browser- or network-specific
Where permitted by your organization’s sign-in policy, try a private browser session or the application’s direct link to distinguish a stale session or an application-path problem. OpenAI’s troubleshooting guidance identifies VPNs, proxies, browser extensions, firewalls, and other network controls as possible blockers of authentication requests. Check the network path and required domains rather than broadly disabling security controls.
7. Choose the next action from the evidence
- Status page confirms a provider incident: Follow provider updates and avoid repeated configuration changes while service recovery is underway.
- Status is operational, but one user is affected: Review that user’s sign-in reason, MFA state, account status, assignment, provisioning, and identity mapping.
- Status is operational, but one application is affected: Check its SAML settings, application-side logs, returned claims, and expected account identifier.
- Failures vary by browser or network: Investigate session state and network controls with the organization’s approved test methods.
For an escalation, include the correlation ID, timestamp and time zone, error code and text, affected account and application, the failure stage, relevant SAML request or response details, and recent configuration changes. Microsoft notes that the correlation ID and timestamp help support engineers locate a SAML issue. Share only the minimum diagnostic data needed, and never include credentials or live tokens.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

