Prompt
Our Azure AD SSO keeps failing during customer onboarding
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
Sorry you’re hitting that. Azure AD SSO failures during onboarding are usually caused by a small set of issues. Here’s a fast triage checklist to narrow it down:
First: what’s the exact failure?
If you can share any of these, I can help pinpoint it quickly:
- The error message shown to the customer
- Whether the failure happens on:
- login redirect
- callback / ACS
- token validation
- user provisioning / SCIM
- Whether it works for some tenants but not others
- Your SSO protocol: SAML or OIDC/OAuth
- Any Azure AD / Entra ID sign-in log error code
Common causes
1) Reply URL / Redirect URI mismatch
Very common during onboarding.
- The exact URL in Azure must match your app’s callback URL
- Watch for:
httpvshttps- trailing slash differences
- different subdomains
- environment mismatch: staging vs prod
2) Identifier / Entity ID mismatch
For SAML:
- Identifier (Entity ID) in Azure must match your SP entity ID exactly
- ACS URL must also be correct
3) Certificate / signing issues
For SAML:
- Expired or rotated signing certificate
- App expecting a different thumbprint / cert than Azure is using
For OIDC:
- Client secret expired
- Wrong client secret copied
- Token signing key validation issues due to stale metadata/caching
4) Tenant consent / admin consent not completed
Especially in onboarding flows:
- Customer has not granted admin consent
- App permissions not approved
- Multi-tenant app settings are incomplete
5) User assignment required
In Azure Enterprise Apps:
- If “Assignment required?” is enabled, the user must be assigned to the app
- This often looks like “login succeeded but access denied”
6) Claim / attribute mapping problems
For SAML:
- NameID format mismatch
- Missing email/UPN claim
- App expects a specific claim that isn’t being sent
For OIDC:
- Missing
email,preferred_username, or group claims - Overly large group claims causing token issues
7) Incorrect tenant configuration in your onboarding
If customers self-configure:
- Wrong tenant ID
- Wrong issuer URL
- Wrong metadata URL
- Using common endpoint when you require a tenant-specific endpoint
8) Conditional Access / MFA / device compliance
Azure sign-in logs may show:
- blocked by Conditional Access
- MFA required but not satisfied
- device compliance policy failing
9) Clock skew / token lifetime issues
Less common, but happens if:
- your servers are out of sync
- SAML assertions are being rejected as “not yet valid” or “expired”
10) SCIM provisioning failing after SSO succeeds
If onboarding includes user provisioning:
- SSO may work, but provisioning fails because:
- SCIM endpoint auth is wrong
- bearer token invalid
- provisioning URL incorrect
- attribute mapping errors
Best next step
Ask the customer to check: Microsoft Entra ID → Sign-in logs → failed sign-in Then capture:
- Failure reason
- Conditional Access result
- App name
- Correlation ID
- Timestamp
If you want, send me:
- SAML or OIDC
- The exact error text
- Any Azure sign-in log error code / correlation ID
- Your callback/ACS URL pattern
…and I’ll help you diagnose it step by step.