Windows
SSO app assignment group missing the user
The external app connection could not be used because the group assigned for SSO did not include the user. The user was added to the correct group and the app assignment was updated to use that group.
Killed once by someone from XL.net, on 2026-03-31.
Affects
Apps
- single sign-on application
What you see
- The user could not complete the connector setup or sign in through SSO even after the identity-side setup was completed.
Why it happens
Likely The user was not a member of the group assigned to the application for SSO access.
When it shows up
A cloud app uses group-based SSO access and the user still cannot connect after the identity provider has been linked
You are in this case if:
- The application is assigned to a group in the identity platform.
- The affected user is not a member of that assigned group.
- The app access depends on group membership rather than direct user assignment.
1 fix below
The steps that killed it
The steps are behind a quick check
There are two ways in and both take a few seconds. Signing in opens the steps on every bug page; so does reading the picture.
Or answer this
Drawing a picture for you.
Can't read it? Sign in instead.
Someone from XL.net killed this on a Windows computer on 2026-03-31. It is written up from that one repair, so it cites no outside page.