Please review the following common issues with SSO integration. If your problem is not on this list or the proposed solutions do not work, please contact support for more assistance.
| Problem | Possible Cause | Solution |
|---|---|---|
|
The user encounters an error page: "unable to log you in" |
User is attempting to sign-in using an expired session. |
This often happens if the user had incorrectly bookmarked the SSO signin page itself, which uses temporary session tokens which will not allow signing in after they expired.
|
| User is attempting to sign-in using a different tenant or with a personal account. |
Users may have accounts with many different tenants in Microsoft Entra ID (formerly Azure Active Directory).
|
|
|
The user encounters an error: "Need Admin Consent" |
An admin for the Entra AD tenant has not granted Epicor CPQ permission to connect. |
If "SSO Signin" is enabled, an admin usually simply needs to login and go through the steps to consent to the permissions Epicor CPQ requires.
|
| After attempting sign-up, the login page does not authenticate the user despite the user having verified the correct credentials. | An incorrect Tenant ID has been specified in the Integration Settings |
The correct Tenant ID in the integration settings is typically in the format of "yourcompany.onmicrosoft.com."
|
| User is attempting to sign-in using a different tenant or with a personal account. |
Users may have accounts with many different tenants in Microsoft Entra ID (formerly Azure Active Directory).
|
|
|
After attempting to sign-up or sign-in the user encounters the error: "AADSTS50011: The reply url specified in the request does not match the reply urls configured for the application" |
Support needed. | Please contact Epicor CPQ support to resolve this issue. |
| The user does not have access to Epicor CPQ despite authenticating properly via Azure Active Directory. | User does not belong to any AD groups which are mapped to Epicor CPQ roles |
A user must belong to at least one AD group which is mapped to a CPQ role, or they must have the "Company Administrator" role.
|
| The user must re-authenticate too often. | The user session lifetime is set too short. | If your users or automated processes must re-enter their username/password too often, solutions include:
Remember to use settings which align with your company's standards. |