This article reviews the most frequent causes of SSO errors during login in Acubiz as well as the corresponding solutions.
Contents of this article:
- 1. Email domain is not configured for SSO in Acubiz
- 2. User access is not created in the company’s AD (Error: AADSTS50105)
- 3. Error 401: Not Authorized
- 4. Configuration when using Package Managers (MDM / Intune)
- 5. SAML certificate needs renewal
- 6. SSO in app: Saved Microsoft login cookie for personal email
1. Email domain is not configured for SSO in Acubiz
-
Error symptom: The user is rejected immediately after entering their email address with the message:
"Selected user account does not exist in tenant..."
- Cause: The company’s email domain has not yet been added to Acubiz’s ADFS configuration. This typically happens when the company creates new email domains after the primary SSO implementation.
- Solution: The company must make an agreement with Acubiz Support to add and configure the new domain (note that adding additional domains incurs an extra cost).
- Performed by: Acubiz Support (by agreement).
2. User access is not created in the company’s AD (Error: AADSTS50105)
-
Error symptom: The user receives the following error message when logging in:
"AADSTS50105: The signed in user 'user@domain.com' is not assigned to a role for the application '4d020abe-0f94-4443-b515-5c40f482ea90' (Acubiz EMS)."
Cause: Missing user permissions in the company’s own Active Directory / Entra ID. The error message is generated by the company’s own system, not by Acubiz.
Solution: The user must be granted access to the Acubiz application in the company’s Entra ID / AD.
Performed by: The company’s internal IT department.
Useful link: Microsoft Documentation: Error Code AADSTS50105
3. Error 401: Not Authorized
Error symptom: SSO authentication is successfully completed by Microsoft, but Acubiz then returns the message "401 Not authorized".
-
Cause(s):
- The user’s email address is not found on an active profile in Acubiz.
- The registered email address in Acubiz does not match the user’s primary email address (User Principal Name) in Entra ID (e.g., when using an email alias).
- There is a duplicate in Acubiz (e.g., a departing/inactive user profile with the same email address).
-
Solution(s):
Create or activate the user profile with the correct email address.
Ensure that the email address in Acubiz exactly matches the user’s primary email address in Entra ID.
Rename the email address on inactive or departing profiles (e.g., by adding
_resignedafter the address). An email address can only be assigned to one profile in Acubiz at a time.
Performed by: The company’s Acubiz Pro-User / Administrator.
Verification: Have the user perform an SSO connection test in Acubiz after the change.
4. Configuration when using Package Managers (MDM / Intune)
- Error symptom: Nothing happens when the user enters their email address in the Acubiz application.
- Cause: When using Mobile Device Management (MDM) such as Microsoft Intune, the required browser is missing in the created app sandbox. Without access to a browser, the app cannot open the company’s AD login page.
- Solution: Configure the deployment in the MDM system so that the app sandbox has access to an approved browser.
- Performed by: The company’s IT department / MDM administrator.
5. SAML certificate needs renewal
Error symptom: SSO login fails for all users in the company due to an expired certificate.
Cause: The company’s SAML certificate has expired (certificates typically have a lifespan of 3 years).
Solution: Renew the certificate in the company’s own system under the existing
FederationMetadataURL. Acubiz ADFS will automatically detect and load the new certificate within 24 hours. It is not necessary to send the certificate file to Acubiz. See Updating the SAML certificatePerformed by: The company’s IT department.
6. SSO in app: Saved Microsoft login cookie for personal email
Error symptom: When attempting SSO login in the app, the user is automatically redirected through a personal Microsoft account, resulting in an error message from the company’s Entra ID.
Cause: A saved Microsoft login cookie in the device’s browser is automatically reused by the app.
-
Solution: Delete cookies and site data for Microsoft on the mobile device:
-
iPhone (Safari):
Check if Safari is the default browser under Settings > Apps > Default Apps.
Go to Settings > Apps > Safari > Advanced > Website Data.
Search for
login.microsoftonline.comand delete data for this domain (or choose Remove All Website Data).
-
iPhone / Android (Chrome):
Open Chrome and go to Settings.
Select Clear Browsing Data (select Cookies and site data).
Confirm deletion.
-
Performed by: The user themselves.
Complete list of error codes from Entra:
https://learn.microsoft.com/en-us/entra/identity-platform/reference-error-codes
Comments
0 comments
Please sign in to leave a comment.