Troubleshooting
Published 28 April 2025
This page details some issues you may encounter with setting up and using SSO.
"Your e-mail address domain didn't match one of the Single Sign-on configuration's verified domains"
We use home realm discovery during login.
After a successful login with your IdP the domain in the email claim must match one of the verified domains you chose when you configured Single Sign-on.
Hence you may need to add all possible email domains and UPN domains to your Single Sign-on configuration.
Users can then enter their UPN at the initial prompt if required by your IdP, rather than their email.
Unable to log in to any account
If SSO is misconfigured on the Redgate side or on your identity provider, it is possible to get into a state where it is not possible to log in with any account. This can prevent fixing the problem, as it becomes impossible to log into the Portal to make changes to SSO.
The Portal SSO recovery flow can be used to disable SSO in this case. You will need to be able to modify the DNS records for the configured domain(s) to prove ownership by adding a TXT record. Once SSO is disabled, you will be able to log in again via username and password and can then reconfigure SSO correctly.
"Sorry, your login failed"
If you see this message when signing in through your identity provider (IdP), the most common cause is an Azure AD Conditional Access policy blocking the sign-in request.
Conditional Access policies are often set up to enforce things like multi-factor authentication, device compliance, or location restrictions. These policies can end up blocking the authentication request from Redgate's SSO integration before it completes, even though your SSO configuration itself is correct.
How to fix it
We recommend creating a client secret for the application registration used in your SSO setup, and adding an exclusion for it in your Conditional Access policy in Microsoft Entra:
- Follow our guide on configuring a client secret to create a client secret for the application registration used in your Redgate SSO connection.
- In the Microsoft Entra admin center, go to Identity > Protection > Conditional Access and open the policy that's blocking the sign-in.
- Under Exclude, add the application (or its service principal) as an exception to the policy.
- Save the policy and try signing in again.
If you're not sure which Conditional Access policy is causing the block, your Entra admin can check the sign-in logs for the failed attempt — the logs show which policy applied and why the sign-in was denied.
If you're still unable to sign in after this, contact Support.
This documentation contains proprietary information and is protected by copyright law.
Copyright © 2026 Red Gate Software Limited. All rights reserved