SSO Login Issues
Where to Find It
Admin portal > Organization settings > Authentication
Use this guide when a user can authenticate with the identity provider but cannot reach the expected ema workspace or project.
Symptoms
- users are redirected back to login
- domain-based SSO discovery is not appearing
- users authenticate successfully with the provider but do not land in ema
- newly provisioned users still cannot access the platform
First Checks
SSO Login Triage
- Confirm the correct tenant and provider are configured.
- Confirm the user is signing in with the expected email domain.
- Verify whether the user exists and has the expected role assignment.
- Check whether the issue is authentication, provisioning, or application authorization.
Likely Causes
- incorrect provider configuration
- stale or incomplete domain setup
- SCIM created the user but roles were never assigned
- admins expected SSO to replace app-level permission configuration
SSO does not grant project access by itself
After the identity provider authenticates the user, ema still needs the right organization, role, and project assignments. Check both authentication and authorization before escalating.
Was this page helpful?