Paytia SSO – Troubleshooting Microsoft Entra Sign-In Issues

Paytia SSO – Troubleshooting Microsoft Entra Sign-In Issues

Paytia SSO – Troubleshooting Microsoft Entra Sign-In Issues

Overview

Paytia supports Single Sign-On (SSO) using Microsoft Entra ID.

When a user signs in to Paytia using their Microsoft organisational account, the authentication request is processed by the customer's own Microsoft Entra tenant.

Each organisation can apply its own security, identity and access policies to Microsoft Entra authentication.

This means Paytia cannot predict in advance how another organisation's Microsoft Entra configuration will respond to the Paytia SSO application.

A Paytia SSO login may therefore work correctly for one organisation but be blocked, challenged or restricted by another organisation's Microsoft Entra policies.


Typical Paytia SSO scenario

When a user selects Sign in with Microsoft from Paytia, the authentication process is:

User

Paytia

Microsoft Entra ID

Customer organisation policies applied

Authentication allowed or rejected

User returned to Paytia

If Microsoft Entra rejects or interrupts the authentication before returning the user to Paytia, the issue may be caused by a policy or configuration within the customer's Microsoft environment.

The Microsoft Entra sign-in logs should normally be the first place to investigate.


1. Check the Microsoft Entra sign-in attempt

The customer's Microsoft Entra administrator should first review the sign-in logs.

Navigate to:

Microsoft Entra admin centre
Entra ID
Monitoring & health
Sign-in logs

Locate the failed sign-in attempt for the user trying to access Paytia.

Review the following information:

  • Status

  • Failure reason

  • Error code

  • Application

  • Resource

  • Authentication details

  • Conditional Access

This is normally the quickest way to establish why Microsoft Entra rejected, challenged or interrupted the Paytia SSO request.

Where possible, record the error code and failure reason before making any configuration changes.


2. Check Conditional Access policies

Navigate to:

Microsoft Entra admin centre
Entra ID
Conditional Access
Policies

Look for policies that may apply to:

  • The user signing into Paytia.

  • A group containing the user.

  • The Paytia enterprise application.

  • All cloud applications or resources.

  • External or third-party applications.

Conditional Access policies may enforce requirements such as:

  • Require multi-factor authentication (MFA).

  • Require a specific authentication strength.

  • Require a compliant device.

  • Require a Microsoft Entra joined device.

  • Require access from an approved or named location.

  • Block access.

  • Restrict external or third-party applications.

Any of these controls may affect the Paytia SSO authentication flow.


3. Identify which Conditional Access policy affected Paytia

Within the relevant Microsoft Entra sign-in event, select:

Conditional Access

Microsoft Entra should show which Conditional Access policies were evaluated and the result of each policy.

Results may include:

  • Success

  • Failure

  • Not applied

  • Report-only

If a policy reports Failure, that policy should be reviewed by the organisation's Microsoft Entra administrator.

Do not assume that Conditional Access needs to be disabled.

The objective is to identify why the policy does not permit the Paytia SSO authentication and determine whether the policy is operating as intended.


4. Check for other organisation-specific Microsoft Entra policies

Conditional Access is not the only Microsoft Entra control that may affect Paytia SSO.

Other organisation-specific controls may include:

  • Enterprise application access restrictions.

  • User assignment requirements.

  • Application consent restrictions.

  • Administrator consent requirements.

  • Authentication strength policies.

  • MFA requirements.

  • Microsoft Entra Identity Protection policies.

  • Device compliance requirements.

  • Named location restrictions.

  • Tenant restrictions.

  • External application restrictions.

  • Organisation-specific information-security policies.

The exact configuration will differ between Microsoft Entra tenants.

Paytia therefore cannot provide a single Microsoft Entra configuration that will work for every organisation.


5. Check the Paytia enterprise application

The Microsoft Entra administrator should also review the Paytia application within Microsoft Entra.

Navigate to:

Microsoft Entra admin centre
Entra ID
Enterprise applications
Paytia

Review:

  • Properties

  • Users and groups

  • Permissions

  • Sign-in logs

  • Conditional Access

Pay particular attention to whether:

Assignment required?

is enabled.

If user assignment is required, the user or an appropriate group may need to be explicitly assigned access to the Paytia enterprise application before SSO can succeed.


Some organisations prevent individual users from granting consent to third-party applications.

In these environments, a Microsoft Entra administrator may need to approve the Paytia application before users can authenticate.

The user may see a Microsoft message indicating that:

  • Administrator approval is required, or

  • The application cannot be accessed until the required consent has been granted.

This should be reviewed by the customer's Microsoft Entra administrator.

The administrator should confirm whether the organisation's application consent policy allows the Paytia application and whether any required administrator consent has been completed.


7. Do not broadly disable Microsoft Entra security policies

Paytia does not recommend disabling Microsoft Entra security controls simply to make SSO work.

For example, do not automatically disable:

  • Conditional Access.

  • MFA.

  • Device compliance requirements.

  • Authentication strength requirements.

  • Organisation-wide security policies.

Instead, identify the exact policy or control affecting the Paytia authentication request.

If an exception or policy change is required, the customer's Microsoft Entra or information-security administrator should determine the smallest appropriate change that allows Paytia SSO while maintaining the organisation's security requirements.


8. Why Paytia SSO behaviour can differ between customers

Microsoft Entra policies are controlled independently by each organisation.

For example:

Organisation A

Policy: Paytia SSO is permitted.
Result: The user authenticates successfully.

Organisation B

Policy: Third-party applications can only be accessed from a managed or compliant device.
Result: The Paytia SSO login may be challenged or blocked when the device does not meet the organisation's requirements.

Organisation C

Policy: Administrator approval is required before users can access new enterprise applications.
Result: The user cannot complete the initial Paytia SSO login until the Paytia application has been approved.

These differences are controlled by the customer's Microsoft Entra configuration rather than by Paytia.


9. Information to provide Paytia Support

If the organisation cannot identify the cause of the failed SSO authentication, provide Paytia Support with as much of the following information as possible:

  • The user attempting to sign in.

  • Date and time of the failed authentication.

  • Microsoft Entra error code.

  • Failure reason.

  • Application shown within the Microsoft Entra sign-in event.

  • Conditional Access result.

  • Name of any Conditional Access policy showing Failure.

  • Screenshot of the failed Microsoft Entra sign-in event.

  • Screenshot of the Conditional Access results.

  • Confirmation that the Paytia enterprise application is visible within Microsoft Entra.

  • Whether user assignment is required.

  • Whether administrator consent has been granted.

Important security information

Do not provide Paytia Support with:

  • Passwords.

  • MFA or one-time authentication codes.

  • Access tokens.

  • Refresh tokens.

  • Client secrets.

  • Private keys.

Paytia Support does not require this information to investigate an SSO authentication issue.


Paytia SSO troubleshooting flow

Use the following troubleshooting sequence when investigating a Microsoft Entra SSO failure:

User selects Sign in with Microsoft

Microsoft Entra authentication starts

Authentication fails or is interrupted

Check Microsoft Entra sign-in logs

Identify the error code and failure reason

Check Conditional Access results

Identify any policy showing Failure

Check the Paytia enterprise application

Check user or group assignment requirements

Check administrator consent requirements

Check organisation-specific security and access policies

Adjust only the policy or configuration causing the issue, where appropriate

Retry Paytia SSO


So to wrap up

When Microsoft Entra SSO to Paytia fails, the key troubleshooting step is to determine what the customer's Microsoft Entra tenant is doing with the Paytia authentication request.

Paytia does not control the customer's Conditional Access, application consent, device compliance, authentication or information-security policies.

Because these policies vary between organisations, Paytia cannot predict in advance how another organisation's Microsoft account or Microsoft Entra tenant will respond when authenticating to Paytia.

The Microsoft Entra sign-in logs should therefore be used to identify the exact policy, configuration or security control affecting the Paytia SSO login before any Microsoft Entra configuration changes are made.

If the Microsoft Entra authentication is successful and the user is returned to Paytia but cannot complete the login, the issue may instead require investigation by Paytia Support.