SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

Fix Google SSO app_not_enabled_for_user Error in Segment

Issue

When attempting to log in to the Segment Console using Google Single Sign-On (SSO), users with the agent role may receive the error message app_not_enabled_for_user or find themselves unable to access their workspace. This login blocker typically affects users with agent roles while administrator accounts continue to log in successfully.

 

Product

Twilio Segment

 

Environment

Segment Console

 

Cause

This issue typically occurs when:

  • The user’s email domain is not fully verified or SSO is not enforced for the domain in the Segment Admin Center.
  • The user’s role or attributes are not correctly set in the Identity Provider (IdP), such as Google Admin.
  • The user exists in multiple workspaces, or there is a stale or misconfigured workspace association.
  • The user is not present in the Segment Admin Center, or SSO is not enabled for their account.

 

Resolution

Follow these steps to resolve the login issue for agent roles using SSO:

  1. Verify Domain and SSO Enforcement

    • Ensure the user’s email domain is verified in the Segment Admin Center.
    • Confirm that SSO is enforced for the domain in the SSO profile settings.
  2. Check User Role and Attributes in IdP

    • In your Identity Provider (e.g., Google Admin), confirm the user’s role is set as agent and all required attributes are correct.
  3. Confirm User Presence in Segment Console

    • Make sure the user exists in the Segment Admin Center and SSO is enabled for their account.
    • If the user was previously associated with multiple workspaces, ensure they are logging into the correct workspace.
  4. Direct SSO Login for Agents

    • For agent roles, Segment allows direct SSO login without manual addition in the console, as long as SSO is enforced for the domain.
  5. Collect Error Details if Issue Persists

    • If the problem continues, collect any error messages or Trace IDs from the browser’s developer console and share them with support for further investigation.

 

Additional Information 

  • If a duplicate or incorrect workspace was previously created, ensure it is deleted or merged, and the user is only associated with the correct workspace.
  • Changes in SSO enforcement or workspace associations may take a few minutes to propagate.
  • For more details on SSO setup and troubleshooting, refer to Segment’s SSO documentation.

 

Have more questions? Submit a request
Powered by Zendesk