SSO login failed" user is not assigned to this application
Fixes SSO login failures where the user is not assigned to the application by adding the IdP app assignment directly or via group. Use when any IdP rejects login with a not-assigned error. Not for authentication failures or in-app permission errors.
TL;DR
Same root cause as the Okta variant: the identity is fine, the app assignment is missing. Add the user to the app's assignment list in the identity provider, wait for group propagation if group-based, and retry.
"SSO login failed" user is not assigned to this applicationUse this when
- Any IdP (Okta, Entra, Google) rejects SSO login with a not-assigned error.
- The user authenticates to the IdP successfully.
- The failure is per-user, not org-wide.
Not for this skill when
- The IdP login itself fails. That is authentication.
- The app opens but denies an action. That is in-app authorization.
- Nobody can log in. That is app or IdP config.
Steps
- Identify which IdP issued the error. Verify: you are fixing assignment in the right console.
- Open the app's assignment list in that IdP. Verify: the user or their group is actually missing.
- Add the user directly or to an assigned group. Verify: the assignment is recorded.
- If group-based, wait several minutes for propagation. Verify: the user shows as effectively assigned.
- Retry the login. Verify: the SSO flow completes.
Variant phrasings
SAML user not assigned
The protocol-first phrasing.
"application not assigned" SSO
The message-first search.
IdP access denied
The generic phrasing.
Compatibility: Okta, Microsoft Entra ID, Google Workspace, and any SAML or OIDC IdP with app assignments.
Why it happens
Assignment is the authorization gate for SSO apps in every major IdP. HR-driven provisioning creates the identity, but the app assignment is a separate grant that is easy to miss for new hires and team movers.
Edge cases / pitfalls
- Just-in-time provisioning creating the user in the app without the IdP assignment firing.
- Group propagation delays making a fresh assignment look broken for several minutes.
- Assignment present but an app-level sign-on policy denying; check both layers.
- The user assigned under a different username format than the one they log in with.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstxs5T4uYrgnYtFuPr30Cwg