Paytia supports Single Sign-On (SSO) using Microsoft Entra ID.
When a user signs in to Paytia using their Microsoft organisational account, the authentication request is processed by the customer's own Microsoft Entra tenant.
Each organisation can apply its own security, identity and access policies to Microsoft Entra authentication.
This means Paytia cannot predict in advance how another organisation's Microsoft Entra configuration will respond to the Paytia SSO application.
A Paytia SSO login may therefore work correctly for one organisation but be blocked, challenged or restricted by another organisation's Microsoft Entra policies.
When a user selects Sign in with Microsoft from Paytia, the authentication process is:
User
↓
Paytia
↓
Microsoft Entra ID
↓
Customer organisation policies applied
↓
Authentication allowed or rejected
↓
User returned to Paytia
If Microsoft Entra rejects or interrupts the authentication before returning the user to Paytia, the issue may be caused by a policy or configuration within the customer's Microsoft environment.
The Microsoft Entra sign-in logs should normally be the first place to investigate.
The customer's Microsoft Entra administrator should first review the sign-in logs.
Navigate to:
Microsoft Entra admin centre
→ Entra ID
→ Monitoring & health
→ Sign-in logs
Locate the failed sign-in attempt for the user trying to access Paytia.
Review the following information:
Status
Failure reason
Error code
Application
Resource
Authentication details
Conditional Access
This is normally the quickest way to establish why Microsoft Entra rejected, challenged or interrupted the Paytia SSO request.
Where possible, record the error code and failure reason before making any configuration changes.
Navigate to:
Microsoft Entra admin centre
→ Entra ID
→ Conditional Access
→ Policies
Look for policies that may apply to:
The user signing into Paytia.
A group containing the user.
The Paytia enterprise application.
All cloud applications or resources.
External or third-party applications.
Conditional Access policies may enforce requirements such as:
Require multi-factor authentication (MFA).
Require a specific authentication strength.
Require a compliant device.
Require a Microsoft Entra joined device.
Require access from an approved or named location.
Block access.
Restrict external or third-party applications.
Any of these controls may affect the Paytia SSO authentication flow.
Within the relevant Microsoft Entra sign-in event, select:
Conditional Access
Microsoft Entra should show which Conditional Access policies were evaluated and the result of each policy.
Results may include:
Success
Failure
Not applied
Report-only
If a policy reports Failure, that policy should be reviewed by the organisation's Microsoft Entra administrator.
Do not assume that Conditional Access needs to be disabled.
The objective is to identify why the policy does not permit the Paytia SSO authentication and determine whether the policy is operating as intended.
Conditional Access is not the only Microsoft Entra control that may affect Paytia SSO.
Other organisation-specific controls may include:
Enterprise application access restrictions.
User assignment requirements.
Application consent restrictions.
Administrator consent requirements.
Authentication strength policies.
MFA requirements.
Microsoft Entra Identity Protection policies.
Device compliance requirements.
Named location restrictions.
Tenant restrictions.
External application restrictions.
Organisation-specific information-security policies.
The exact configuration will differ between Microsoft Entra tenants.
Paytia therefore cannot provide a single Microsoft Entra configuration that will work for every organisation.
The Microsoft Entra administrator should also review the Paytia application within Microsoft Entra.
Navigate to:
Microsoft Entra admin centre
→ Entra ID
→ Enterprise applications
→ Paytia
Review:
Properties
Users and groups
Permissions
Sign-in logs
Conditional Access
Pay particular attention to whether:
Assignment required?
is enabled.
If user assignment is required, the user or an appropriate group may need to be explicitly assigned access to the Paytia enterprise application before SSO can succeed.
Some organisations prevent individual users from granting consent to third-party applications.
In these environments, a Microsoft Entra administrator may need to approve the Paytia application before users can authenticate.
The user may see a Microsoft message indicating that:
Administrator approval is required, or
The application cannot be accessed until the required consent has been granted.
This should be reviewed by the customer's Microsoft Entra administrator.
The administrator should confirm whether the organisation's application consent policy allows the Paytia application and whether any required administrator consent has been completed.
Paytia does not recommend disabling Microsoft Entra security controls simply to make SSO work.
For example, do not automatically disable:
Conditional Access.
MFA.
Device compliance requirements.
Authentication strength requirements.
Organisation-wide security policies.
Instead, identify the exact policy or control affecting the Paytia authentication request.
If an exception or policy change is required, the customer's Microsoft Entra or information-security administrator should determine the smallest appropriate change that allows Paytia SSO while maintaining the organisation's security requirements.
Microsoft Entra policies are controlled independently by each organisation.
For example:
Policy: Paytia SSO is permitted.
Result: The user authenticates successfully.
Policy: Third-party applications can only be accessed from a managed or compliant device.
Result: The Paytia SSO login may be challenged or blocked when the device does not meet the organisation's requirements.
Policy: Administrator approval is required before users can access new enterprise applications.
Result: The user cannot complete the initial Paytia SSO login until the Paytia application has been approved.
These differences are controlled by the customer's Microsoft Entra configuration rather than by Paytia.
If the organisation cannot identify the cause of the failed SSO authentication, provide Paytia Support with as much of the following information as possible:
The user attempting to sign in.
Date and time of the failed authentication.
Microsoft Entra error code.
Failure reason.
Application shown within the Microsoft Entra sign-in event.
Conditional Access result.
Name of any Conditional Access policy showing Failure.
Screenshot of the failed Microsoft Entra sign-in event.
Screenshot of the Conditional Access results.
Confirmation that the Paytia enterprise application is visible within Microsoft Entra.
Whether user assignment is required.
Whether administrator consent has been granted.
Do not provide Paytia Support with:
Passwords.
MFA or one-time authentication codes.
Access tokens.
Refresh tokens.
Client secrets.
Private keys.
Paytia Support does not require this information to investigate an SSO authentication issue.
Use the following troubleshooting sequence when investigating a Microsoft Entra SSO failure:
User selects Sign in with Microsoft
↓
Microsoft Entra authentication starts
↓
Authentication fails or is interrupted
↓
Check Microsoft Entra sign-in logs
↓
Identify the error code and failure reason
↓
Check Conditional Access results
↓
Identify any policy showing Failure
↓
Check the Paytia enterprise application
↓
Check user or group assignment requirements
↓
Check administrator consent requirements
↓
Check organisation-specific security and access policies
↓
Adjust only the policy or configuration causing the issue, where appropriate
↓
Retry Paytia SSO
When Microsoft Entra SSO to Paytia fails, the key troubleshooting step is to determine what the customer's Microsoft Entra tenant is doing with the Paytia authentication request.
Paytia does not control the customer's Conditional Access, application consent, device compliance, authentication or information-security policies.
Because these policies vary between organisations, Paytia cannot predict in advance how another organisation's Microsoft account or Microsoft Entra tenant will respond when authenticating to Paytia.
The Microsoft Entra sign-in logs should therefore be used to identify the exact policy, configuration or security control affecting the Paytia SSO login before any Microsoft Entra configuration changes are made.
If the Microsoft Entra authentication is successful and the user is returned to Paytia but cannot complete the login, the issue may instead require investigation by Paytia Support.