Home

login authentication struggle - see screenshot

%3CLINGO-SUB%20id%3D%22lingo-sub-251277%22%20slang%3D%22en-US%22%3Elogin%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-251277%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20colleague%20of%20mine%20is%20trying%20to%20get%20access%20to%20Microsoft%20Teams%20(guest%20access).%20When%20she%20tries%20to%20log%20into%20the%20client%20tenant%20she%20gets%20a%20dialog%20box%20asking%20for%20username%20and%20password%20(see%20attachement).%20she's%20tried%20her%20company%20%2F%20client%20email%20address%20with%20no%20luck.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20anyone%20help%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3EEmer%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-251277%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Elogin%20screen%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252745%22%20slang%3D%22en-US%22%3ERe%3A%20login%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252745%22%20slang%3D%22en-US%22%3E%3CP%3EI%20recently%20was%20tasked%20with%20troubleshooting%20this%2C%20and%20despite%20what%20the%20other%20say%2C%20got%20it%20to%20work%20where%20the%20user%20authenticates%20against%20their%20org's%20Azure%20ID%2FOffice365%20ID.%20In%20my%20test%20cases%2C%20this%20was%20achieved%20by%20acknowledging%20the%20invite%20basically%20in%20a%20browser%20private%20session%20at%20first%2C%20which%20then%20should%20allow%20them%20to%20get%20to%20an%20authentication%20process%20that%20sets%20up%20some%20sort%20of%20'federation'%20from%20what%20I%20can%20tell.%20THat%20process%20has%20to%20complete%20via%20authenticating%20as%20the%20'email'%20that%20was%20invited.%20if%20your%20login%20ID%20is%20a%20upn%20different%20than%20the%20email%2C%20it%20won't%20work.%3C%2FP%3E%3CP%3EI%20tested%20this%20with%20both%20personal%20MS%20accounts%2C%20and%20an%20office365%20tenant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20break%20it%20down%3A%3C%2FP%3E%3CP%3Eif%20invitee%20is%20on%20authenticated%20windows%20device%3A%3C%2FP%3E%3CP%3ELogin%20to%20owa%2Foutlook.com%20in%20a%20private%20browser%2C%20none%20chrome%20window.%26nbsp%3B%3C%2FP%3E%3CP%3EClick%20the%20teams%20link%20in%20the%20window%20or%20copy%20%26amp%3B%20paste%20it%20%26amp%3B%20open%20it%20in%20another%20private%20tab.%3C%2FP%3E%3CP%3EFollow%20authentication%2Ffederation%20approval%20stuff.%3C%2FP%3E%3CP%3EIf%20prompted%20to%20open%20teams%20client%2C%20it%20may%20pop%20up%20stuff%20about%20switching%20ID's.%3C%2FP%3E%3CP%3EThis%20part%20is%20touchy%2C%26nbsp%3B%20if%20your%20teams%20and%20desktop%20are%20integrated%20to%20Azure%20AD%2C%20so%20I%20wrote%20my%20documentation%20to%20tell%20users%20to%20try%20to%20complete%20in%20the%20private%20browser%20session.%3C%2FP%3E%3CP%3EOnce%20that%20completes%20once%2C%20in%20the%20browser%20session%2C%20between%20the%20teams%20search%20%26amp%3B%20the%20Users%20ID%20icon%2C%20should%20be%20a%20pull%20down%20that%20switch's%20between%20each%20org.%3C%2FP%3E%3CP%3EThen%20they%20should%20be%20able%20to%20open%20the%20teams%20client%20as%20their%20main%20org%2C%20and%20should%20see%20the%20pull%20down.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EMac's%20actually%20follow%20this%20process%20easier.%3C%2FP%3E%3CP%3EAnd%20whats%20not%20easy%20is%20if%20you%20try%20to%20log%20out%20of%20teams%20on%20an%20authenticated%20windows%20machine%2C%20and%20login%20as%20another%20org's%20ID%20as%20primary..%20The%20client%20barf's%20a%20high%20percentage%20of%20the%20time.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252698%22%20slang%3D%22en-US%22%3ERe%3A%20login%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252698%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Vasil%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252697%22%20slang%3D%22en-US%22%3ERe%3A%20login%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252697%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Chris!%20Will%20give%20that%20a%20try%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-252029%22%20slang%3D%22en-US%22%3ERe%3A%20login%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-252029%22%20slang%3D%22en-US%22%3Eyeah%20Teams%20and%20guest%20access%20are%20no%20fun%20right%20now.%20If%20they%20have%20office%20365%20tenant%20on%20the%20address%20you%20invite%20as%20a%20guest%2C%20the%20client%20wants%20to%20default%20to%20their%20local%20tenant%20first%20before%20redirecting%20to%20the%20guest%20tenant.%20If%20teams%20is%20prevented%20in%20any%20way%20on%20their%20home%20tenant%20you%20won't%20be%20able%20to%20join%20a%20tenant%20as%20a%20guest.%3CBR%20%2F%3E%3CBR%20%2F%3EMy%20advice%20and%20what%20I've%20been%20using%20if%20I%20can't%20get%20people%20into%20my%20Team%20on%20first%20try%20due%20to%20login%20issues%20or%20work%20%2F%20personal%20overlap%20issues%2C%20I%20have%20the%20user%20just%20create%20or%20use%20a%20different%20Microsoft%20Account%20and%20invite%20it%20to%20your%20Team.%20At%20least%20until%20they%20fix%20this%20issue.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-251361%22%20slang%3D%22en-US%22%3ERe%3A%20login%20authentication%20struggle%20-%20see%20screenshot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-251361%22%20slang%3D%22en-US%22%3E%3CP%3ELooks%20like%20she's%20hitting%20the%20company's%20own%20AD%20FS%20server%2C%20and%20the%20only%20way%20she%20can%20authenticate%20against%20it%20is%20if%20she%20has%20a%20regular%20user%20account.%20Advise%20her%20to%20try%20to%20access%20the%20Team%20in%20a%20private%20browser%20session%20instead.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hi there, 

 

A colleague of mine is trying to get access to Microsoft Teams (guest access). When she tries to log into the client tenant she gets a dialog box asking for username and password (see attachement). she's tried her company / client email address with no luck. 

 

Can anyone help?

 

Thanks, 

Emer 

5 Replies

Looks like she's hitting the company's own AD FS server, and the only way she can authenticate against it is if she has a regular user account. Advise her to try to access the Team in a private browser session instead.

yeah Teams and guest access are no fun right now. If they have office 365 tenant on the address you invite as a guest, the client wants to default to their local tenant first before redirecting to the guest tenant. If teams is prevented in any way on their home tenant you won't be able to join a tenant as a guest.

My advice and what I've been using if I can't get people into my Team on first try due to login issues or work / personal overlap issues, I have the user just create or use a different Microsoft Account and invite it to your Team. At least until they fix this issue.

Thanks Chris! Will give that a try

Thanks Vasil

I recently was tasked with troubleshooting this, and despite what the other say, got it to work where the user authenticates against their org's Azure ID/Office365 ID. In my test cases, this was achieved by acknowledging the invite basically in a browser private session at first, which then should allow them to get to an authentication process that sets up some sort of 'federation' from what I can tell. THat process has to complete via authenticating as the 'email' that was invited. if your login ID is a upn different than the email, it won't work.

I tested this with both personal MS accounts, and an office365 tenant.

 

To break it down:

if invitee is on authenticated windows device:

Login to owa/outlook.com in a private browser, none chrome window. 

Click the teams link in the window or copy & paste it & open it in another private tab.

Follow authentication/federation approval stuff.

If prompted to open teams client, it may pop up stuff about switching ID's.

This part is touchy,  if your teams and desktop are integrated to Azure AD, so I wrote my documentation to tell users to try to complete in the private browser session.

Once that completes once, in the browser session, between the teams search & the Users ID icon, should be a pull down that switch's between each org.

Then they should be able to open the teams client as their main org, and should see the pull down. 


Mac's actually follow this process easier.

And whats not easy is if you try to log out of teams on an authenticated windows machine, and login as another org's ID as primary.. The client barf's a high percentage of the time.

Related Conversations
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
28 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
2 Replies
*Updated 9/3* Syncing in Microsoft Edge Preview Channels
Elliot Kirk in Articles on
202 Replies
Early preview of Microsoft Edge group policies
Sean Lyndersay in Discussions on
65 Replies