SOLVED

RestrictSigninToPattern breaks logon into AAD tennant with Beta 83.0.487.37??

Steel Contributor

Good morning,

This morning I noticed that my profile was not synching to my AAD account, synchronisation not available.

Trying to fix this with logging off and on again I get the message:

Your system administrator has not granted login permissions for krsh@han.nl. You can try another email address or contact the system administrator for more information. 

After removing the setting "RestrictSigninToPattern" https://docs.microsoft.com/nl-nl/DeployEdge/microsoft-edge-policies#restrictsignintopattern which was set to our domain and worked nicely t'ilI last week I was able to logon again...

Can somebody @Pernille-Eskebo look into this? We want to roll out Edge to +6000 devices on the 27th and we want to do that without these kind of issues.

 

regards, Henno

 

 

5 Replies
And works again, seems a small glitch in AAD for a couple of minutes. I hope we don't get that on the 27th...

@Henno_Keers Thanks for bringing this to our attention. I'm glad to hear that this is working again, but I'll still check-in with our Sync and Identity teams and let you know if they have any further thoughts.

 

Fawkes (they/them)
Project & Community Manager - Microsoft Edge

best response
Solution

@Deleted we found out this morning, shortly before rollout, that we made a small error in how the RestrictSigninToPattern setting was configured.

It should have read: .*han.nl

But was: *han.nl

Small thing, missing a . When trying to logon users where confronted with:

"Your system Administrator has not granted user@han.nl signin permissions"

 

Oh well....

 

regards, Henno

@Henno_Keers Glad to hear that it was an easy fix; we love those!

 

Fawkes (they/them)
Project & Community Manager - Microsoft Edge

1 best response

Accepted Solutions
best response
Solution

@Deleted we found out this morning, shortly before rollout, that we made a small error in how the RestrictSigninToPattern setting was configured.

It should have read: .*han.nl

But was: *han.nl

Small thing, missing a . When trying to logon users where confronted with:

"Your system Administrator has not granted user@han.nl signin permissions"

 

Oh well....

 

regards, Henno

View solution in original post