New user cannot access Esper tenant after admin invitation
Android
When a newly invited user tries to access your Esper tenant, they may be unable to log in or receive an access denied error even after the invitation email was sent.
Why this happens
Esper tenant access requires the user to explicitly accept the invitation before their account becomes active. If the invitation was never accepted, has expired, or was sent with a login method that does not match your tenant's authentication configuration, the user cannot complete sign-in.
Steps to resolve
- Check the user's invitation status. In the Esper Console, go to Users & Groups → Users and locate the affected email address. A status of Pending means the invitation has not yet been accepted. A status of Active means the account exists but something else is blocking login — skip to step 4.
- Ask the user to accept the invitation. Have the user check their inbox and spam or junk folders for an invitation email from Esper. The user must click the Accept Invitation link in that email before attempting to log in. After accepting, the user should sign in using the login method specified in the invitation — either Esper Credentials or your tenant's Single Sign-On (SSO).
-
Delete and resend the invitation if login still fails. If the user accepted the invitation but still cannot log in, the invitation was likely sent with the wrong login method. In the Esper Console, go to Users & Groups → Users, locate the affected user, and delete the existing invitation. Send a new invitation to the same email address, this time setting the Login Method to match your tenant's authentication configuration:
- If your tenant uses SSO, select Single Sign-On.
- If your tenant uses standard credentials, select Esper Credentials.
- Check for email domain restrictions if SSO is in use. If your tenant enforces SSO and the user's email domain is not permitted by your Identity Provider (IdP), the user will be blocked even with a valid invitation. Confirm with your IdP administrator that the user's email domain is allowed to authenticate.
- Resend the invitation if the original link has expired. Invitation links expire after several days. If the user delayed accepting, the link will no longer work. Delete the old invitation and send a fresh one from Users & Groups → Users.
Verify: In Users & Groups → Users, the affected user's status should show Active. Ask the user to confirm they can fully access the Esper Console. Status typically updates immediately after a successful first login.
If this doesn't resolve it
If multiple users from the same domain cannot log in after accepting invitations, this points to a broader SSO or IdP configuration issue rather than a per-user invitation problem. Contact Esper Support and include the following information:
- The affected email addresses
- Your SSO provider name (for example, Okta, Azure AD, Google Workspace)
- The exact error message the user sees at login
- Whether any users on the same domain can log in successfully
Still need help?
If the issue persists, please submit a support ticket and include the new user's email address, the tenant name, and the exact error message or behavior encountered when attempting to access the Esper tenant.
Please sign in to leave a comment.
Comments
0 comments