ThreatPrevent
ThreatPrevent
Cyber Trust Intelligence
Enterprise SSO

Troubleshooting

Use these checks for the most common configuration and sign-in failures. Authentication responses intentionally avoid exposing private account details.

Provider test fails

Confirm the tenant-specific issuer uses /v2.0, OIDC discovery is publicly reachable and the discovered issuer exactly matches the configured issuer.

Redirect URI mismatch

Register https://api.threatprevent.io/v1/auth/sso/callback exactly as a Web redirect URI in Entra.

Invalid client or secret

Confirm the Application (client) ID, use the secret value rather than its identifier, and check the expiry date.

User cannot be linked

Confirm the user already exists or is invited in ThreatPrevent and their email belongs to the verified organisation domain.

Domain will not verify

Publish the exact TXT name and value displayed in the panel. Allow for DNS propagation, then run verification again.

Portal works but extension fails

Confirm the installed Chrome or Edge extension build is approved for your ThreatPrevent environment, then retry through the system browser.

Email code no longer works

This is expected after mandatory SSO activates. Use company SSO or ask ThreatPrevent support about controlled emergency recovery.

Settings cannot be edited

SSO is scheduled or active. Cancel or disable enforcement before changing the provider, policy or verified domains.

Information to collect

  • Organisation name and affected user's work email
  • Whether the portal, extension or both are affected
  • UTC time of the failed attempt and the visible error message
  • Entra correlation or request ID, when shown
  • Provider test status and secret expiry date

Never send a client secret, access token, refresh token or browser-extension token to support.

Still unable to sign in?

Contact ThreatPrevent with the diagnostic information above. For an enforced organisation-wide outage, identify an authorised recovery contact.

hello@threatprevent.ioSSO overview