Can't access Production tenant with an IdentityNow Admins account

Hi team.

We created a generic account in the IdentityNow Admins source to be managed by multiple users. However, when we send the invitation and set the password, we get a login error “Authentication failed or unauthorized location” even though the credentials are correct.

Login works if we assign the Admin user level to the account, but this account should not have any user level, and assigning one would require using MFA to log in.

This behavior only occurs in production; in the sandbox environment, it works normally.

Should I upload this generic account to a CSV file separate from the IdentityNow Admins CSV, using a different identity profile?

Hi Ariel,

Can you check if the lifecycle state on the account is set to ‘Active’?

Margo

Hi @ArielM - can you verify on the ISC Admins Identity Profile what the Sign In Method and Block Access From settings are? Also Like Margo asked, is the user being correctly assigned to the profile?

Do you have SSO setup to login to ISC tenant? In such case you will not be able to sign in directly to ISC with any accounts besides ADMIN accounts

your admin has restricted the locations in sailpoint isc

Hi everyone.

I have already verified that the lifecycle state is active and that the Sign-In Method and Block Access settings are disabled for the identity profile.

@iamnithesh As you mentioned, SSO via EntraID is enabled in the production tenant, so I assume that is the reason.

Is there a way to log in to the tenant with a generic account that does not have admin privileges?

I don’t think this is possible. See below screenshot

from Configuring Identity Security Cloud as a Service Provider - SailPoint Identity Services