Troubleshooting SSO Access

Please review the following common issues with SSO integration. If your problem is not on this list or the proposed solutions do not work, please contact support for more assistance.

 

Problem Possible Cause Solution

The user encounters an error page:

"unable to log you in"

User is attempting to sign-in using an expired session.

This often happens if the user had incorrectly bookmarked the SSO signin page itself, which uses temporary session tokens which will not allow signing in after they expired.

  • Users should only bookmark the Epicor CPQ page itself, and not any URL starting with "login.microsoftonline.com"
User is attempting to sign-in using a different tenant or with a personal account.

Users may have accounts with many different tenants in Microsoft Entra ID (formerly Azure Active Directory).

  • Ensure the user is signing in with the correct tenant and is selecting the "Work or School Account" option while signing in.

The user encounters an error:

"Need Admin Consent"

An admin for the Entra AD tenant has not granted Epicor CPQ permission to connect.

If "SSO Signin" is enabled, an admin usually simply needs to login and go through the steps to consent to the permissions Epicor CPQ requires.

  • Refer to the setup steps above.
After attempting sign-up, the login page does not authenticate the user despite the user having verified the correct credentials. An incorrect Tenant ID has been specified in the Integration Settings

The correct Tenant ID in the integration settings is typically in the format of "yourcompany.onmicrosoft.com."

  • Verify that you have entered the correct Tenant ID. Ensure everything is spelled correctly.
User is attempting to sign-in using a different tenant or with a personal account.

Users may have accounts with many different tenants in Microsoft Entra ID (formerly Azure Active Directory).

  • Ensure the user is signing in with the correct tenant and is selecting the "Work or School Account" option while signing in.

After attempting to sign-up or sign-in the user encounters the error:

"AADSTS50011: The reply url specified in the request does not match the reply urls configured for the application"

Support needed. Please contact Epicor CPQ support to resolve this issue.
The user does not have access to Epicor CPQ despite authenticating properly via Azure Active Directory. User does not belong to any AD groups which are mapped to Epicor CPQ roles

A user must belong to at least one AD group which is mapped to a CPQ role, or they must have the "Company Administrator" role.

  • Review the group-to-role mappings in Integration Settings to ensure they are correctly defined.
  • Review the CPQ roles this user belongs to: at least one should be mapped to an AD group in Integration Settings.
The user must re-authenticate too often. The user session lifetime is set too short.

If your users or automated processes must re-enter their username/password too often, solutions include:

  • each user can set "Remember Me" to true,
  • an administrator can increase the "User Session Lifetime" to a higher number.

Remember to use settings which align with your company's standards.

 

Was this article helpful?