Troubleshooting
Find the message or symptom you see, then follow the fix. If nothing here matches, see Support for what to send Xertone.
Sign-in and access in Teams
Section titled “Sign-in and access in Teams”Dashboard keeps loading, or sign-in shows AADSTS7000112
Section titled “Dashboard keeps loading, or sign-in shows AADSTS7000112”Symptom. The TeamsPIM Dashboard tab spins and never loads. A sign-in window may show “Sorry, but we’re having trouble signing you in” with:
AADSTS7000112: Application '1fec8e78-bce4-4aaf-ab1b-5451cc387264'(Microsoft Teams) is disabled.Cause. Your tenant has disabled sign-in for the Microsoft Teams enterprise application. TeamsPIM signs users in through Teams, so it cannot get a token.
Fix. An administrator with the Cloud Application Administrator or Application Administrator role re-enables sign-in for the Microsoft Teams enterprise app.
In the Microsoft Entra admin center:
- Go to Enterprise apps > All applications.
- Remove the “Application type == Enterprise Applications” filter. Microsoft’s own apps are hidden while it is applied.
- Search for
1fec8e78-bce4-4aaf-ab1b-5451cc387264and open Microsoft Teams. - Open Properties, set “Enabled for users to sign-in?” to Yes, and select Save.
Or with Microsoft Graph PowerShell:
Connect-MgGraph -Scopes "Application.ReadWrite.All"$Sp = Get-MgServicePrincipal -Filter "appId eq '1fec8e78-bce4-4aaf-ab1b-5451cc387264'"Update-MgServicePrincipal -ServicePrincipalId $Sp.Id -AccountEnabled:$trueThen wait a few minutes, fully quit Teams and start it again.
Teams on the web uses a different application, Microsoft Teams Web Client
(5e3ce6c0-2b1f-4285-8d4b-75ee78787346). If the error names that ID, apply the same fix to it: search
for that ID in the admin center, or use it in place of 1fec8e78-bce4-4aaf-ab1b-5451cc387264 in the
PowerShell above.
Microsoft documents this property in Disable user sign-in for an application and Properties of an enterprise application.
Other sign-in and access problems
Section titled “Other sign-in and access problems”| Symptom | Cause | Fix |
|---|---|---|
| “No TeamsPIM license assigned” | The user has no TeamsPIM licence. | An administrator assigns one on the Licenses page of the Customer Admin Portal. The user then reopens the app. See Assign licences. |
| “The license check could not be completed. Please try again.” | TeamsPIM could not finish checking the licence. | Try again. If it keeps happening, contact support. |
| “We couldn’t sign you in. Check your connection and try again.” | Sign-in could not complete, often a network problem. | Check the connection and select Try again. |
| “Set up multi-factor authentication” | Your organisation requires MFA and the user has not registered for it. | Register at aka.ms/mfasetup, then sign out of Teams and sign back in. |
| “Additional verification required” | The role’s PIM settings require a Conditional Access authentication context. | Select Verify and complete the sign-in prompt. |
| “Sign in to Teams again to continue” | Multi-factor authentication needs a fresh sign-in. | Sign out of Teams and sign back in. |
| “Switching directory is not set up” | One of the three requirements for Switch Directory is missing. | Make sure the subscription is active, the user has a licence, and additional directories are added in Subscription Settings. See Additional directories. |
| “Open TeamsPIM in Microsoft Teams” | The Dashboard was opened in a browser outside Teams. | Select Open Microsoft Teams and use the TeamsPIM tab there. |
| TeamsPIM did not appear in Teams after a licence was assigned | A Teams app permission policy blocks TeamsPIM, or it is not in your Teams app catalogue. The automatic install fails silently. | Allow TeamsPIM in the Teams admin center, then turn the user’s licence off and on to re-save it. Or the user installs TeamsPIM from the Teams store. See Deploy in Teams. |
| A just-activated role does not show as active yet | Microsoft Entra takes a few seconds to apply the activation. | Wait a few seconds and refresh the tab. |
| “Request creating failed.” followed by another message | Microsoft Entra refused the request. The second part is Entra’s own message. | Act on Entra’s message, for example the role’s settings or an existing pending request for the same role. |
| Azure role requests on a subscription are not handled | TeamsPIM is not assigned to that Azure subscription. Nothing is assigned automatically. | An Owner or User Access Administrator assigns it on the Azure Resources page. See Azure resources. |
Approvals
Section titled “Approvals”| Symptom | Cause | Fix |
|---|---|---|
| An approver gets no approval cards | The approver has no TeamsPIM licence, is not an approver in the role’s PIM settings, or TeamsPIM is not installed for them. | Assign a licence, check the approvers in Entra PIM role settings, and make sure the app is installed. |
| The card shows “To continue please sign in” with Sign In | Approvals run as the approver, so TeamsPIM needs them signed in. This also happens when MFA or Conditional Access needs interaction. | Select Sign In, complete the sign-in, then select Approve or Deny again. |
| “Justification text is required.” | The justification box was empty. | Enter a justification and select the button again. |
| “PIM Request card is stale. The request may have already been processed.” | Another approver already decided, or the request was cancelled or expired. | Nothing to do. The card shows the outcome once it updates. |
| “This request is already being processed. Please wait for the result.” | A decision is in progress. | Wait for the card to update. |
| “Action failed. Please try again or contact support.” | The approval or denial did not go through. | Try again. If it keeps failing, contact support with the time and the card details. |
| “PIM Request not found.” | The request no longer exists in PIM. | Nothing to approve. The requestor can submit a new request if still needed. |
| An approver cannot approve their own request | PIM does not allow self-approval. | Another approver has to decide. |
| The request shows “Expired” | The approval window ran out. PIM, not TeamsPIM, sets it. | The requestor submits a new request. |
Setup and activation
Section titled “Setup and activation”| Symptom | Cause | Fix |
|---|---|---|
| “Subscription not found” on the landing page | The landing page was not opened from the Marketplace. | Open your TeamsPIM subscription in AppSource or the Azure Marketplace and select Configure account now. |
| “Signed in with a different account” | You are not signed in with the purchasing account. | Select Sign out & switch account and sign in as the purchaser. |
| “Admin consent not verified yet. Complete consent and try again.” | Consent was not finished, or was granted in a different tenant. | Complete consent in the same tenant as the purchase and try again. See Admin consent. |
“Your organisation hasn’t approved TeamsPIM yet.” when signing in to the Customer Admin Portal (AADSTS500011 or AADSTS65001) |
TeamsPIM has no admin consent in your tenant. | A Global Administrator grants consent, or you copy the link and send it to one. |
| The Overview stays on Waiting for review | Xertone has not finished reviewing your request. | Wait for the email. If you have questions, contact support. |
| Setup failed on the Overview | Setting up your tenant’s back end failed. | Contact support with your tenant ID. See Review and provisioning. |
Customer Admin Portal
Section titled “Customer Admin Portal”| Symptom | Cause | Fix |
|---|---|---|
| “TeamsPIM has not been approved for your organisation yet.” | TeamsPIM has no admin consent in your tenant. | Select Grant admin consent if you are a Global Administrator, or Copy link and send it to one. |
| “You do not have access to manage this subscription.” | You are neither the purchaser nor an added administrator. | Ask the purchaser to add you under Administrators in Subscription Settings. |
| “User has license assignment.” | The person already holds a TeamsPIM licence under another subscription. | Unassign it under the other subscription first. |
| “Subscription limit exceeded.” | Every seat is in use. | Add seats with Microsoft. See Manage your subscription. |
“This tenant is not linked to the subscription.” (TENANT_NOT_LINKED) |
The tenant is not in the subscription’s additional tenant IDs. | Add it in Subscription Settings. |
“This subscription’s tenant has not granted TeamsPIM admin consent.” (TENANT_CONSENT_MISSING) |
That tenant has not consented to TeamsPIM. | Grant consent for that tenant, then add it in Subscription Settings. |
| “Admin consent is missing for this tenant.” when adding a tenant | Consent was revoked or not completed. | Grant consent again, select Verify, then Add. |
| “This tenant ID cannot be removed.” | It is the subscription’s own tenant. | This tenant always stays on the subscription. |
Azure resources
Section titled “Azure resources”| Symptom | Cause | Fix |
|---|---|---|
“This tenant requires multi-factor authentication to access Azure.” (AZURE_MFA_REQUIRED) |
Your account has not completed MFA in that tenant. | Sign in to portal.azure.com, switch to that directory and complete MFA. Then sign out of the Customer Admin Portal, sign back in and pick the tenant again. |
“You cannot change access at this scope.” (INSUFFICIENT_AZURE_RBAC) |
You are not Owner or User Access Administrator on the Azure subscription. | Get one of those roles, or ask someone who has it to assign TeamsPIM. |
| “Assign app failed.” or “Unassign app failed.” | Azure refused the change. | Read the message under it, fix the cause and try again. |
| An Azure subscription is missing from the list | Your account cannot access it in the selected tenant. | Pick the right tenant in “Select a tenant”, or get access to the subscription. |