Skip to content
English
  • There are no suggestions because the search field is empty.

SSO Troubleshooting: user is not assigned to a role for the application

Learn how to troubleshoot the user is not assigned to a role for the application error.

Error

Error text might be one of things:

  • user is not assigned to a role for the application (Microsoft Azure identity provider)
  • account isn't linked to << organization >>
  • 403 app_not_enabled_for_user "Service is not enabled for this user."  (Google identity provider)

Note: this error text originates from your identity provider and is different for every identity provider product. The text above are examples from various identity provider products.

An error message on your identity provider page (not a EVERFI Foundry) page after a user authenticates successfully to your identity provider, and the error message explains the user is not assigned to the application or similar text.

Explanation

Typically, an identity provider has a mechanism to assign user-groups and/or users to a service provider application like Foundry. If you see an error such as this, then it likely means the user has authenticated to your identity provider, but the user is not assigned the necessary privileges in your identity provider to access the Foundry application.

Resolution

In your identity provider, verify that you have assigned the appropriate security user groups to the Foundry application and that the user who got this error belongs to one of those groups if they should indeed be able to access Foundry.