PARTNER ADMIN GUIDE

Troubleshoot access

Resolve common sign-in, provisioning, domain and role-assignment issues.

Partnership administrator5 min read

Scope: individual tenant

Common access problems

Work through the most likely cause before changing the tenant's identity configuration.

Common tenant access problems, likely causes and actions
ProblemLikely causeAction
SSO client is not provisionedGreentic SSO was selected but the managed client has not been activated.Save the SSO configuration and provision or re-provision the client.
The domain page says Awaiting SSOAn email domain was added before SSO became active.Configure and activate SSO, then return to the Domains tab.
Users do not appearProvisioning has not run, sync is disabled or the identity provider is not connected.Review the SCIM configuration and use Sync now.
A user can sign in but cannot use a Designer capabilityThe required capability role has not been assigned.Open Roles and grant the minimum required capability.
A user appears in the tenant but not in the expected teamIdentity provisioning and team membership are separate.Open Teams and review the team's Members list.

SSO client is not provisioned

Greentic SSO has been selected but the managed client has not been activated, so sign-in through SSO will not work.

Troubleshooting example only — the SSO client is not provisioned.
  1. 1Open Access → SSO & users → SSO.
  2. 2Confirm that Greentic SSO is selected.
  3. 3Save the SSO configuration.
  4. 4Select Re-provision SSO client.
  5. 5Confirm that the SSO client status becomes Active.

The Domains tab says Awaiting SSO

An email domain was added before SSO became active, so the domain is not routing anywhere yet.

Troubleshooting example only — domains configured before SSO is ready.
  1. 1Configure and activate SSO for the tenant.
  2. 2Return to Access → SSO & users → Domains.
  3. 3Confirm that the Awaiting SSO notice has cleared.
  4. 4Start domain verification.
Always test with a normal user accountAn administrator's existing session may hide routing, permissions or onboarding problems.

Related guides

Back to Access and sign-in