The intended audience for this article is Technical Agent Admins with SSO.
A range of edge cases can lead to errors during user creation or syncing when working with Single Sign-On and Directory Sync. Below are brief descriptions of the most common cases and ways to resolve the errors.
User Creation Fails
When a user cannot be created in Wunderite after being added to the identity provider, a notification will be sent to all administrators of the team who have Single Sign-On alert notifications turned on.
When a user cannot be created, first check the Directory Sync Health table for any outstanding action items. If the user has a conflict that needs to be resolved by the Wunderite team, there will be an indication of this on the table along with the action to be taken.
If there are no related issues in the Directory Sync Health table, check that the user has all the required attributes (email, first name, last name) and belongs to the correct role group and segment group (if segments are enabled) in the identity provider. If the user belongs to a group that maps to a segment in Wunderite, ensure segments are enabled in Wunderite. If segments are not enabled in Wunderite, you will need to remove the user from the group to enable them to log in.
If the user is in the correct group in the identity provider and still cannot be created confirm that your user license limit has not been reached by reviewing the notification email or by contacting Wunderite Customer Success. If you need more licenses, please let Wunderite Customer Success know.
User Login Fails
When a user cannot log in due to a configuration error (e.g. no active organization membership, no segment assignment or an invalid role) or there are more than 5 login failures in 5 minutes, a notification will be sent to all administrators of the team who have Single Sign-On alert notifications turned on.
If a single user is unable to log in, check in the identity provider to ensure the user is in the identity provider. If the user is not present in the identity provider, they will need to be added. If the user is present in the identity provider, ensure that they are active. Once active, you can check the user is unlocked in Wunderite by logging in as an Administrator, navigating to Team in the lefthand menu, and then selecting Team Members. Search for the user and check that their account is unlocked. If the user is not present in the list of Team Members, then there may be an issue with their account creation. See our troubleshooting guide for additional information.
If a large number of users are having trouble logging in please check that the identity provider integration is working as expected. You can do this by logging into Wunderite as an Administrator, navigating to Team in the left-hand menu, selecting Team Security and then selecting Manage SSO in WorkOS. Once inside the WorkOS portal, review the identity provider connection for any configuration or connection issues. If you are unable to log in to Wunderite, please contact Wunderite Customer Success to assist.
User's Email Needs to Be Updated
If a user's email address needs to be updated, you will need to contact Wunderite Customer Success to ensure the change is made correctly in Wunderite without creating a duplicate account.
