SSO login returns "You do not have access to this tenant" after invite link is clicked
Android
When a user clicks an SSO invitation link and signs in through their identity provider, they see the error You do not have access to this tenant and cannot reach the Esper Console.
Why this happens
This error occurs when the user's identity provider account has not been fully linked to their Esper tenant. The most common cause is an expired or previously used invitation link — the user must complete the SSO invitation flow exactly once from a fresh link before their account is active. An incomplete or inactive SSO configuration on the tenant can also block the link from working.
Steps to resolve
- Confirm your SSO connection is active. In the Esper Console, navigate to Company Settings → Single Sign-On. Verify that your identity provider connection is fully saved and shown as active. If the connection appears incomplete or disabled, finish the SSO setup before continuing — an inactive connection will cause all invitation links to fail.
- Locate the affected user. Navigate to Company Settings → User Management and find the user by their email address. Check whether an SSO invitation was previously sent to them.
- Revoke the existing invitation. If an invitation was already sent, revoke it. This invalidates the old link and prevents the same error from recurring if the user clicks it again.
- Generate and send a fresh SSO invitation. From Company Settings → User Management, create a new SSO invitation for the affected user and send it to their email address.
- Have the user complete sign-in through their identity provider. The user must click the new invitation link from their email and authenticate through your identity provider (for example, the Microsoft 365 or Okta login screen). They should not attempt to sign in directly at the Esper Console login page — the invitation flow must be completed through the identity provider first to create the account link.
Credential-based login and SSO
Esper supports credential-based login (email and password) and SSO simultaneously on the same tenant. However, a user designated for SSO access must complete the SSO invitation flow — they cannot use credential-based login as a fallback. If you want to prevent credential-based login entirely, disable it under Company Settings → Single Sign-On.
If this doesn't resolve it
If the error persists after resending the invitation, or if your SSO configuration is not saving correctly, contact Esper Support with the following information:
- Your tenant ID
- The affected user's email address
- Your identity provider type (for example, Azure AD, Okta, or Google Workspace)
- A screenshot of the
You do not have access to this tenanterror
Still need help?
If you're still unable to access your tenant after clicking the invite link, please submit a support ticket and include your email address, the tenant name, and whether you're using SSO or local authentication.
Please sign in to leave a comment.
Comments
0 comments