Skip to content
IT Atlas

Troubleshooting · Identity

User cannot sign in

Authentication fails for one user, or for a group of users, across one or more applications.

7 checks

Work through these in order

  1. 01

    Confirm the scope

    One user, one application, one location, or everyone? Scope immediately separates account issues from policy or outage issues.

  2. 02

    Check account state

    Enabled, not locked, password not expired, licence assigned where required.

  3. 03

    Read the sign in log

    The failure reason and the applied policy are recorded, this usually ends the investigation.

  4. 04

    Check access policy

    Conditional Access or equivalent: was the request blocked by device compliance, location or risk?

  5. 05

    Check MFA state

    Registered methods present, device time correct for TOTP, no recent method changes.

  6. 06

    Check on premises dependencies

    For hybrid: directory synchronisation health, domain controller availability, time skew for Kerberos.

  7. 07

    Confirm the application trust

    Certificate expiry, reply URLs, or a broken federation trust affect all users of one application.

Background reading

Other guides