Troubleshooting
Microsoft sign-in troubleshooting
Resolve Microsoft Entra ID (Azure AD) sign-in errors such as consent, tenant restrictions, and redirect mismatches.
Microsoft sign-in uses your organization's Microsoft Entra ID (formerly Azure AD). Most failures fall into one of the cases below. The sign-in result screen shows a reference ID — keep it for support.
Admin consent required
Some Entra tenants require an administrator to approve an application before members can sign in. If you see a consent error, ask your Microsoft tenant administrator to grant consent for OSTaaS, then retry.
You are in the wrong tenant
If your account belongs to multiple Microsoft tenants, make sure you pick the organizational account tied to your OSTaaS workspace, not a personal Microsoft account.
Redirect mismatch
A "redirect URI mismatch" means the address Microsoft returned to does not match what is registered. This is an operator configuration issue — see Callback mismatch and share your reference ID with your workspace owner.
MFA / conditional access
If your organization enforces MFA or conditional access, complete the challenge in the Microsoft window before returning. A blocked popup can interrupt this — allow popups and retry.
Still stuck
Contact support with your reference ID. For how the flow is secured, see Authentication overview.
Related
Related documentation
- Sign-in troubleshootingResolve the most common Microsoft and social sign-in problems, using the reference ID from the sign-in result screen.
- Callback (redirect URI) mismatchWhat a redirect URI mismatch means after a provider redirect, and how workspace owners resolve it.
- Authentication & securityHow sign-in works under the hood, including sessions, providers, and the deterministic result screen.