TrainMeUK LogoTrainMeUK
Home
How It Works
Product
Reports
Pricing
Resources
Login

Summer sale

Limited time

15% off monthly · +20% annual

15%off monthly+20%off annual
Claim offer
Help
Help Center
Adding DepartmentsUser Roles & PermissionsPassword Policy & MFAManaging Inactive & Returning UsersPersonal & Shared Email DomainsTroubleshooting SSO & SCIM
Adding DepartmentsUser Roles & PermissionsPassword Policy & MFAManaging Inactive & Returning UsersPersonal & Shared Email DomainsTroubleshooting SSO & SCIM
HelpUser ManagementTroubleshooting SSO & SCIM

Troubleshooting SSO & SCIM

Fix common Azure AD SSO login and SCIM provisioning problems

Who this applies to

Admins fixing SSO login failures or SCIM sync issues. Learners only need the correct sign-in method once configuration is healthy.

Required permissions

  • TrainMeUK Admin — SSO & Provisioning and Manage Users
  • Entra Global Admin / Application Admin — consent, Redirect URI, provisioning logs

Note

Full setup steps live in Setting Up Azure AD SSO and SCIM. This page is symptom → check only. SSO and SCIM are independent — you can use SSO without SCIM.

What happens automatically

SCIM creates, updates, or deactivates users only while Entra provisioning is configured and running for assigned groups. SSO alone does not create users unless SCIM (or another create path) is also in place.

SSO login symptoms

SymptomLikely causeCheckPermissionTell support
Needs admin approvalApp consent not granted in Microsoft 365A Global Admin / Application Admin must sign in once to approve the appMicrosoft adminTenant domain + that consent was never completed
Redirect error during SSORedirect URI mismatchAdmin → System Settings → SSO & Provisioning: Redirect URI must match Entra app registration exactly (https and trailing slash)LMS admin + Entra adminBoth Redirect URI values (TrainMeUK vs Entra)
SSO button missing / not redirectedSSO disabled or domain not allowedEnable SSO; Domain Configuration → Allowed Domains; Auto-redirect if expectedLMS adminWhether SSO is enabled and user email domain
User can SSO but account InactiveAccount disabled in LMSUser Management → Enable; or check SCIM deactivationLMS adminUser email + Active/Inactive badge

SCIM provisioning symptoms

SymptomLikely causeCheckPermissionTell support
SCIM test connection failsWrong endpoint/token or SCIM offSSO & Provisioning → Enable SCIM on; copy SCIM Endpoint URL and SCIM Bearer Token exactly into Entra Tenant URL / Secret TokenLMS admin + Entra adminWhether Enable SCIM is on (do not paste the bearer token in tickets)
User does not appear after syncNot in assigned Entra group / mapping errorUser in assigned group; Entra Provisioning logs; user email not already in another orgEntra adminProvisioning log error text + user UPN
Leaver still Active in LMSSCIM not configured or user not in scopeConfirm SCIM provisioning is running; or Disable manually in User ManagementLMS / Entra adminWhether SCIM is enabled and last successful sync time from Entra

Related

  • Setting Up Azure AD SSO and SCIM
  • Personal & Shared Email Domains
  • Troubleshooting Login & Welcome Email
Previous

Personal & Shared Email Domains

TrainMeUK LogoTrainMeUK Ltd

Connect Azure once. TrainMeUK handles reminders, Teams nudges, certificates, and audit-proof reports — automatically.

hello@trainmeuk.co.uk
+44 1252 929213
8 George Myers Close, Ash, Guildford, Surrey, GU12 6FW

Quick Links

  • Home
  • How It Works
  • Product
  • Reports
  • Pricing
  • Resources
  • Knowledge Base

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Addendum
  • Subprocessors
  • Acceptable Use Policy
  • FAQ

Popular Resources

Mandatory Training Requirements for UK BusinessesHow Often GDPR Training Should Be Done in the UKHow Fast You Should Produce Training Records for Auditors

© 2026 TrainMeUK Ltd. All rights reserved.

CPD Accredited Provider